keycloak-httpd-client-install Insecure Secrets
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 7, 2023
Description
Published by the National Vulnerability Database
Jan 20, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 26, 2023
Last updated
Sep 7, 2023
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
References