Back to bug 1906797

Who When What Removed Added
Guilherme de Almeida Suckevicz 2020-12-11 17:30:55 UTC Summary keycloak: Exploiting the client registration API CVE-2020-27838 keycloak: Exploiting the client registration API
Alias CVE-2020-27838
Paramvir jindal 2020-12-14 09:28:40 UTC See Also https://issues.redhat.com/browse/KEYCLOAK-16612
Paramvir jindal 2021-01-11 09:48:21 UTC CC aileenc, akoufoud, alazarot, almorale, anstephe, avibelli, bgeorges, bibryam, cmoulliard, dkreling, etirelli, ganandan, ggaughan, hbraun, ibek, ikanello, janstey, jochrist, jpallich, jstastny, jwon, kverlaen, lthon, mnovotny, mszynkie, pantinor, pgallagh, rrajasek, rruss, rsynek, sdaley
Paramvir jindal 2021-01-11 09:49:34 UTC CC gmalinko
Paramvir jindal 2021-02-09 10:05:20 UTC Doc Text A flaw was found in keycloak where client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication. This could be a confidentiality issue if the same PUBLIC client changed to CONFIDENTIAL later.
Eric Christensen 2021-02-16 19:49:12 UTC Doc Text A flaw was found in keycloak where client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication. This could be a confidentiality issue if the same PUBLIC client changed to CONFIDENTIAL later. A flaw was found in keycloak. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
Michael 2021-02-16 23:51:24 UTC CC mvk37
Paramvir jindal 2021-03-08 06:56:36 UTC Fixed In Version keycloak 13.0.0
Red Hat Bugzilla 2021-12-31 23:33:48 UTC CC almorale
Red Hat Bugzilla 2022-04-19 04:38:55 UTC CC ggaughan
Red Hat Bugzilla 2022-06-30 23:46:52 UTC CC bibryam
Red Hat Bugzilla 2022-08-12 04:38:12 UTC CC etirelli
Red Hat Bugzilla 2022-08-31 22:23:07 UTC CC mszynkie
Red Hat Bugzilla 2022-10-28 13:13:00 UTC CC krathod
Red Hat Bugzilla 2022-11-14 23:22:41 UTC CC jstastny
Red Hat Bugzilla 2022-12-31 23:43:16 UTC CC aboyko
Red Hat Bugzilla 2023-05-15 18:03:49 UTC CC rrajasek
Red Hat Bugzilla 2023-05-15 18:09:21 UTC CC drieden
Red Hat Bugzilla 2023-05-31 22:25:00 UTC CC rsynek
Red Hat Bugzilla 2023-07-07 08:35:12 UTC Assignee security-response-team nobody

Back to bug 1906797