CVE-2020-1724: Medium severity red hat keycloak vulnerability
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Other sources
Personal information contained in the Account Manager section can be shown to a user about another user already disconnected (logout) by the keycloak platform.
Reference : https://issues.jboss.org/browse/KEYCLOAK-10641
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1724?
CVE-2020-1724 is a vulnerability found in Keycloak versions before 9.0.2 that allows a malicious user to view the personal information of a previously logged-out user.
How severe is CVE-2020-1724?
CVE-2020-1724 has a severity rating of 4.3, which is considered medium.
How can I fix CVE-2020-1724?
To fix CVE-2020-1724, you need to upgrade your Keycloak installation to version 9.0.2 or later.
Where can I find more information about CVE-2020-1724?
You can find more information about CVE-2020-1724 in the official Red Hat Security Advisory RHSA-2020:2107 and RHSA-2020:2106.
What is the Common Weakness Enumeration (CWE) for CVE-2020-1724?
The CWE for CVE-2020-1724 is CWE-613, which is a design flaw vulnerability.