CVE-2020-1724

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/05/2020
Last modified:
07/11/2023

Description

A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* 9.0.2 (excluding)
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools