Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2022-40705 Vulnerability in maven package soap:soap
CVE-2021-21380 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ratings-api
CVE-2023-36468 Vulnerability in maven package org.xwiki.platform:xwiki-platform-core
CVE-2019-20365 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core