Description
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1724
Related Vulnerabilities
CVE-2020-2142 Vulnerability in maven package org.jenkins-ci.plugins:p4
CVE-2020-27838 Vulnerability in maven package org.keycloak:keycloak-client-registration-api
CVE-2020-2218 Vulnerability in maven package org.jenkins-ci.plugins:hp-quality-center
CVE-2018-1304 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-24831 Vulnerability in maven package org.apache.iotdb:iotdb-grafana-connector