Description
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1698
Related Vulnerabilities
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-rt-core
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-api
CVE-2020-13940 Vulnerability in maven package org.apache.nifi:nifi-bootstrap
CVE-2020-10688 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2019-1003028 Vulnerability in maven package org.jenkins-ci.plugins:jms-messaging