Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 Maven

Keycloak leaks sensitive information in logged exceptions

GHSA-qgmm-f2qw-r95f · CVE-2020-1698

Published · Modified

Description

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.

Ready to move

Start Securing

Free, no credit card | First findings in minutes