keycloak: Password leak by logged exception in HttpMethod class
Published May 11, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.37%
Description
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Affected products
-
Affected
- All versions before 9.0.0
No data.
Red Hat Runtimes Spring Boot 2.2.6
keycloak-core
Fixed · RHSA-2020:2252
Red Hat Single Sign-On 7.4.0
n/a
Fixed · RHSA-2020:5625
Text-Only RHOAR
n/a
Fixed · RHSA-2020:2905
Red Hat Decision Manager 7
keycloak-core
Not affected
Red Hat Fuse 7
keycloak-core
Fix deferred
Red Hat Mobile Application Platform 4
keycloak-core
Out of support scope
Red Hat OpenShift Application Runtimes
keycloak-core
Affected
Red Hat Process Automation 7
keycloak-core
Not affected
Red Hat Single Sign-On 7
rh-sso7-keycloak
Affected
Red Hat support for Spring Boot
keycloak-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Runtimes Spring Boot 2.2.6 | keycloak-core | Fixed | RHSA-2020:2252 |
| Red Hat Single Sign-On 7.4.0 | n/a | Fixed | RHSA-2020:5625 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2020:2905 |
| Red Hat Decision Manager 7 | keycloak-core | Not affected | n/a |
| Red Hat Fuse 7 | keycloak-core | Fix deferred | n/a |
| Red Hat Mobile Application Platform 4 | keycloak-core | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | keycloak-core | Affected | n/a |
| Red Hat Process Automation 7 | keycloak-core | Not affected | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Affected | n/a |
| Red Hat support for Spring Boot | keycloak-core | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2020-1698 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1790292 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1698 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4970 Advisory
- https://github.com/advisories/GHSA-qgmm-f2qw-r95f Advisory
- https://github.com/keycloak/keycloak/commit/62c9e1577618470832ede22dcedd46cba15b1836
- https://github.com/keycloak/keycloak/pull/6751
- https://nvd.nist.gov/vuln/detail/CVE-2020-1698
- https://www.cve.org/CVERecord?id=CVE-2020-1698
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub