Описание
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in keycloak. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Decision Manager 7 | keycloak-core | Not affected | ||
| Red Hat Fuse 7 | keycloak-core | Fix deferred | ||
| Red Hat Mobile Application Platform 4 | keycloak-core | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | keycloak-core | Affected | ||
| Red Hat Process Automation 7 | keycloak-core | Not affected | ||
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Affected | ||
| Red Hat support for Spring Boot | keycloak-core | Affected | ||
| Red Hat Runtimes Spring Boot 2.2.6 | keycloak-core | Fixed | RHSA-2020:2252 | 01.06.2020 |
| Red Hat Single Sign-On 7.4.0 | Fixed | RHSA-2020:5625 | 17.12.2020 | |
| Text-Only RHOAR | Fixed | RHSA-2020:2905 | 23.07.2020 |
Показывать по
Дополнительная информация
Статус:
5 Medium
CVSS3
Связанные уязвимости
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in keycloak in versions before 9.0.0. A logged except ...
Keycloak leaks sensitive information in logged exceptions
5 Medium
CVSS3