QID 995240
Date Published: 2023-10-04
QID 995240: Java (Maven) Security Update for org.keycloak:keycloak-core (GHSA-5q66-v53q-pm35)
A flaw was discovered in Keycloak Core package. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular attributes in the users attributes. The password is also created, but the user attributes must not be there. This way, any entities (all users and clients with proper rights/roles) are able to retrieve the users passwords in clear-text.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5q66-v53q-pm35 for updates and patch information.
Vendor References
- GHSA-5q66-v53q-pm35 -
github.com/advisories/GHSA-5q66-v53q-pm35
CVEs related to QID 995240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5q66-v53q-pm35 | org.keycloak:keycloak-core |
|