Back

MEDIUM

keycloak: Password leak by logged exception in HttpMethod class

Published May 11, 2020

Description

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 11, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date May 6, 2020
Bugzilla 1790292

ENISA EUVD

Assigner redhat
Published May 11, 2020
Updated Aug 4, 2024