CVE-2024-4540 describes an information disclosure vulnerability in Keycloak's OAuth 2.0 Pushed Authorization Requests (PAR) implementation. Client-provided parameters are inadvertently stored in plain text within the KC_RESTART cookie, which is returned in the authorization server's HTTP response. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity that could lead to significant information disclosure without requiring user interaction. The potential impact is primarily on confidentiality. Currently, there is no evidence of active exploitation, nor is public exploit code available. Community discussion and media coverage for this CVE are minimal, suggesting low awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Single Sign-On 7.6 For RHEL 7 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Single Sign-On 7.6 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Single Sign-On 7.6 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Build Of Keycloak 22 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Build Of Keycloak 24 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.