CVE-2020-1724 PUBLISHED CVSS 4.3 MEDIUM

Reported by redhat · Published May 11, 2020

A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.

Risk Scores

CVSS v3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Red HatkeycloakAll versions before 9.0.2
Red HatkeycloakAll versions before 9.0.2, All versions before 9.0.2, All versions before 9.0.2
npmkeycloak-connect0, 0, 0
Mavenorg.keycloak:keycloak-core0, 0, 0
Mavenorg.keycloak:keycloak-services0, 0, 0

Timeline

References

Open in Interactive Console →