---
id: CVE-2024-10973
title: A vulnerability was found in Keycloak
summary: >-
  A vulnerability was found in Keycloak. The environment option
  `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication
  configuration is always used in plain text which can allow an attacker that
  has access to adjacent n…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-319
published: '2024-12-17'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-10973'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2024-10973'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2324361'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00266
epssPercentile: 0.16747
ingestedAt: '2026-08-04T07:38:00.179Z'
---

## Overview

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
