CVE-2020-1698
published 2020-05-11CVE-2020-1698: A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.37%
29.4th percentile
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 9.0.0 | 9.0.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak leaks sensitive information in logged exceptions
ghsa·2022-05-24
CVE-2020-1698 [MEDIUM] CWE-200 Keycloak leaks sensitive information in logged exceptions
Keycloak leaks sensitive information in logged exceptions
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
OSV
Keycloak leaks sensitive information in logged exceptions
osv·2022-05-24
CVE-2020-1698 [MEDIUM] Keycloak leaks sensitive information in logged exceptions
Keycloak leaks sensitive information in logged exceptions
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Red Hat
keycloak: Password leak by logged exception in HttpMethod class
vendor_redhat·2020-05-06·CVSS 5.0
CVE-2020-1698 [MEDIUM] CWE-532 keycloak: Password leak by logged exception in HttpMethod class
keycloak: Password leak by logged exception in HttpMethod class
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in keycloak. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Package: keycloak-core (Red Hat Decision Manager 7) - Not affected
Package: keycloak-core (Red Hat Fuse 7) - Fix deferred
Package: keycloak-core (Red Hat Mobile Application Platform 4) - Out of support scope
Package: keycloak-core (Red Hat OpenShift Application Runtimes) - Affected
Package: keycloak-core (Red Hat Process Automatio
No detection rules found.
No public exploits indexed.
2020-05-11
Published