A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An attacker can leverage this to inject malicious content during the realm import procedure. This can lead to unintended consequences within the Keycloak environment.
History

Thu, 21 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for injection attacks when crafted realm documents are processed. An attacker can leverage this to inject malicious content during the realm import procedure. This can lead to unintended consequences within the Keycloak environment.
Title org.keycloak/keycloak-model-storage-service: Variable injection into environment variables Org.keycloak/keycloak-model-storage-service: variable injection into environment variables
First Time appeared Redhat
Redhat build Keycloak
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References

Wed, 20 Aug 2025 00:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.keycloak/keycloak-model-storage-service: Variable injection into environment variables
Weaknesses CWE-526
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-08-21T15:40:25.136Z

Updated: 2025-08-21T15:40:25.136Z

Reserved: 2025-08-19T13:11:49.675Z

Link: CVE-2025-9162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-08-21T16:15:35.067

Modified: 2025-08-21T16:15:35.067

Link: CVE-2025-9162

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-19T00:00:00Z

Links: CVE-2025-9162 - Bugzilla