First published: Mon Jan 13 2020(Updated: )
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Keycloak | <9.0.0 | |
redhat/keycloak | <9.0.0 | 9.0.0 |
maven/org.keycloak:keycloak-core | <9.0.0 | 9.0.0 |
<9.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.