MEDIUM 5.7 Maven

Keycloak on Quarkus CLI option for encrypted JGroups ignored

GHSA-g6qq-c9f9-2772 · CVE-2024-10973

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The env option KC_CACHE_EMBEDDED_MTLS_ENABLED does not work and the jgroups replication configuration is always used in plain. This option worked before in 24 and 22. More info in public issue https://github.com/keycloak/keycloak/issues/34644.

Ready to move

Start Securing

Free, no credit card | First findings in minutes