Description
Keycloak is an open source identity and access management solution.
Acunetix determined that it was possible to access a 'client secret' without authentication.
Remediation
Upgrade to the latest version of KeyCloak
References
Related Vulnerabilities
MediaWiki CVE-2019-12473 Vulnerability (CVE-2019-12473)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2606)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1725)
WordPress Improper Privilege Management Vulnerability (CVE-2020-28036)