PT-2020-14900 · Red Hat · Keycloak
Pedro Sampaio
+1
·
Published
2020-05-11
·
Updated
2022-05-24
·
CVE-2020-1698
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 9.0.0
Description
A flaw in the HttpMethod class may leak the password given as a parameter, posing a threat to data confidentiality.
Recommendations
For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data handled by the HttpMethod class until a patch is applied. Avoid using the
password parameter in affected API endpoints until the issue is resolved.Fix
Insertion into Log File
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak