Red Hat Bugzilla – Bug 1511626
CVE-2017-15112 keycloak-httpd-client-install: unsafe use of -p/--admin-password on command line
Last modified: 2018-05-14 08:21:07 EDT
A flaw was discovered in keycloak-httpd-client-install version 0.6-2. The -p/--admin-password option ask for a password through the command line, possibly leaking it via command history.
Created keycloak-httpd-client-install tracking bugs for this issue: Affects: fedora-all [bug 1531307]
Upstream fix: https://github.com/jdennis/keycloak-httpd-client-install/commit/c3121b271abaaa1a76de2b9ae89dacde0105cd75
Statement: Red Hat Product Security has rated this issue as having security impact of Low. This issue may be fixed in a future version of Red Hat Enterprise Linux. OpenStack users please note, this issue is present in: * Red Hat OpenStack Platform 9.0 (Mitaka) * Red Hat OpenStack Platform 10.0 (Newton) * Red Hat OpenStack Platform 11.0 (Ocata) If a fixed version of keycloak-httpd-client-install is made available in Red Hat Enterprise Linux, OpenStack customers should consume this package directly from the Red Hat Enterprise Linux channel (this occurs during normal updates).