Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2021-31406 Vulnerability in maven package com.vaadin:flow-server
CVE-2021-36749 Vulnerability in maven package org.apache.druid:druid-core
CVE-2020-12480 Vulnerability in maven package com.typesafe.play:play_2.11
CVE-2020-1926 Vulnerability in maven package org.apache.hive:hive-service