CVE-2020-27838 - log back

CVE-2020-27838 edited at 09 Mar 2021 09:07:20
Description
- Client registration endpoints should not allow fetching information about public clients without authentication.
+ A security issue was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later.
CVE-2020-27838 edited at 01 Mar 2021 14:41:18
References
https://bugzilla.redhat.com/show_bug.cgi?id=1906797
https://issues.redhat.com/browse/KEYCLOAK-16521
+ https://github.com/keycloak/keycloak/pull/7790
+ https://github.com/keycloak/keycloak/commit/9356843c6c3d7097d010b3bb6f91e25fcaba378c
CVE-2020-27838 edited at 11 Dec 2020 18:09:42
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ Client registration endpoints should not allow fetching information about public clients without authentication.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1906797
+ https://issues.redhat.com/browse/KEYCLOAK-16521
CVE-2020-27838 created at 11 Dec 2020 18:08:52
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes