Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2021-41561 Vulnerability in maven package org.apache.parquet:parquet
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2015-1832 Vulnerability in maven package org.apache.derby:derby
CVE-2020-13692 Vulnerability in maven package org.postgresql:postgresql