REDHAT-BUG-2398025: Low severity Keycloak Keycloak vulnerability

Published Sep 25, 2025
·
Updated

The keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy (see https://www.keycloak.org/server/reverseproxy#exposedpathrecommendations ). The problem is that, at least ha-proxy, can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms (which should be exposed). For example:

curl --path-as-is http://localhost:7080/realms/../admin/master/console/#/master/info <http://localhost:7080/admin/master/console/#/master/info>

The admin path requires authentication but, in the end, the final customer is exposing a path that he thinks is not accessible. Also note that this is more an issue in ha-proxy than keycloak. Keycloak does not even document how to configure ha-proxy or any other proxy, it just recommends to not expose the /admin app. For example mod-proxy correctly manages non-normalized URLs, because it normalizes the path before to be sure it's inside the prefix-path.

Nevertheless we have reached the conclusion that keycloak should return an error by default for non-normalized URLs.

The installation should use a proxy configuration with ha-proxy with the common configuration.

Affected Software

2 affected components
Keycloak Keycloak
HAProxy HAProxy

Event History

Sep 25, 2025
Data Sourced
via Red Hat·03:19 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2398025?

The severity of REDHAT-BUG-2398025 is significant due to potential unauthorized access to the Keycloak admin features.

2

How do I fix REDHAT-BUG-2398025?

To fix REDHAT-BUG-2398025, ensure that the /admin path is not exposed to the public when using a reverse proxy.

3

Which software is affected by REDHAT-BUG-2398025?

REDHAT-BUG-2398025 affects Keycloak and HAProxy installations.

4

What are the risks associated with REDHAT-BUG-2398025?

The risks associated with REDHAT-BUG-2398025 include the potential for attackers to access administrative features and sensitive data.

5

Is REDHAT-BUG-2398025 a known vulnerability in the community?

Yes, REDHAT-BUG-2398025 is a recognized vulnerability that is being documented and discussed in the security community.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203