Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2023-41037 Vulnerability in maven package org.webjars.npm:github-com-openpgpjs-openpgpjs
CVE-2016-10735 Vulnerability in npm package bootstrap
CVE-2023-31101 Vulnerability in maven package org.apache.inlong:manager-dao
CVE-2023-26476 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2020-8203 Vulnerability in maven package org.webjars.bower:lodash