Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2020-2269 Vulnerability in maven package org.jenkins-ci.plugins:chosen-views-tabbar
CVE-2020-36377 Vulnerability in npm package aaptjs
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2020-13925 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2012-6662 Vulnerability in maven package org.fujion.webjars:jquery-ui