Generation of Error Message Containing Sensitive Information in org.keycloak:keycloak-core
CVE-2020-1717
- org.keycloak:keycloak-core
- org.keycloak:keycloak-core-1.0-alpha-1
- org.keycloak:keycloak-core-1.0-beta-1
Summary
A flaw was found in Keycloak. A logged in user can do an account email enumeration attack. NOTE: We couldn't find a fix for this.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- HIGH
- LOW
- NONE
CWE-209 - Generation of Error Message Containing Sensitive Information
The software generates an error message that includes sensitive information about its environment, users, or associated data.
Advisory Timeline
- Published