CVE-2020-1698: Infoleak
A flaw was found in keycloack. A logged exception in the HttpMethod class may leak password given as parameter.
References:
https://issues.redhat.com/browse/KEYCLOAK-12638
Other sources
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1698?
CVE-2020-1698 has a severity rating that indicates a high threat to data confidentiality.
How do I fix CVE-2020-1698?
To fix CVE-2020-1698, upgrade Keycloak to version 9.0.0 or later.
What software is affected by CVE-2020-1698?
CVE-2020-1698 affects versions of Keycloak prior to 9.0.0.
What type of vulnerability is CVE-2020-1698?
CVE-2020-1698 is a vulnerability that involves the potential leakage of passwords through logged exceptions.
Is CVE-2020-1698 present in Keycloak 9.0.0?
No, CVE-2020-1698 is not present in Keycloak version 9.0.0 or later.