Business information leak In org.keycloak:keycloak-core
Description
Keycloak leaks sensitive information in logged exceptions A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 9.0.0 | ||
npm | 9.0.0 | ||
maven | 9.0.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.