Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2019-14653 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2021-21342 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-1584 Vulnerability in maven package io.quarkus:quarkus-oidc
CVE-2023-45819 Vulnerability in maven package org.webjars.npm:tinymce