Description
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1698
Related Vulnerabilities
CVE-2021-42340 Vulnerability in maven package org.apache.tomcat:tomcat-websocket
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-core
CVE-2022-43183 Vulnerability in maven package com.xuxueli:xxl-job-core
CVE-2015-7559 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2015-5258 Vulnerability in maven package org.springframework.social:spring-social-core