A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
{
"github_reviewed": true,
"github_reviewed_at": "2024-04-22T23:11:33Z",
"severity": "MODERATE",
"nvd_published_at": "2020-05-11T14:15:00Z",
"cwe_ids": [
"CWE-200",
"CWE-532"
]
}