Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4540

24
FAUCET Score

CVE-2024-4540 describes an information disclosure vulnerability in Keycloak's OAuth 2.0 Pushed Authorization Requests (PAR) implementation. Client-provided parameters are inadvertently stored in plain text within the KC_RESTART cookie, which is returned in the authorization server's HTTP response. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity that could lead to significant information disclosure without requiring user interaction. The potential impact is primarily on confidentiality. Currently, there is no evidence of active exploitation, nor is public exploit code available. Community discussion and media coverage for this CVE are minimal, suggesting low awareness at this time.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Single Sign-On 7.6 For RHEL 7
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Single Sign-On 7.6 For RHEL 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Single Sign-On 7.6 For RHEL 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Build Of Keycloak 22
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Build Of Keycloak 24
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 20th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

mavenpatch availablevia ghsa
Product: org.keycloak:keycloak-servicesFixed in: 24.0.5
redhatpatch availablevia redhat_api
Product: Red Hat Build of Keycloak
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-operator-bundle:22.0.11-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-rhel9:22-15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 22Fixed in: rhbk/keycloak-rhel9-operator:22-18
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 24Fixed in: rhbk/keycloak-operator-bundle:24.0.5-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 24Fixed in: rhbk/keycloak-rhel9:24-10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 24Fixed in: rhbk/keycloak-rhel9-operator:24-10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 7Fixed in: rh-sso7-keycloak-0:18.0.14-1.redhat_00001.1.el7sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 8Fixed in: rh-sso7-keycloak-0:18.0.14-1.redhat_00001.1.el8sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 9Fixed in: rh-sso7-keycloak-0:18.0.14-1.redhat_00001.1.el9sso
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso76-openshift-rhel8:7.6-49
View patch

Vendor Advisories (2)

mavenGHSA-69fp-7c8p-crjrhigh

Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

Jun 10, 2024
redhatCVE-2024-4540Low

keycloak: exposure of sensitive information in Pushed Authorization Requests (PAR) KC_RESTART cookie

Jun 3, 2024

References

access.redhat.com / errata/RHSA-2024:3566
access.redhat.com / errata/RHSA-2024:3567
access.redhat.com / errata/RHSA-2024:3568
access.redhat.com / errata/RHSA-2024:3570
access.redhat.com / errata/RHSA-2024:3572
access.redhat.com / errata/RHSA-2024:3573
access.redhat.com / errata/RHSA-2024:3574
access.redhat.com / errata/RHSA-2024:3575
access.redhat.com / errata/RHSA-2024:3576
access.redhat.com / security/cve/CVE-2024-4540
bugzilla.redhat.com / show_bug.cgi