cbcvebase.
CVE-2020-1698
published 2020-05-11

CVE-2020-1698: A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.

Affected

2 ranges
VendorProductVersion rangeFixed in
red_hatkeycloak
redhatkeycloak< 9.0.09.0.0