Bug 1906797 (CVE-2020-27838) - CVE-2020-27838 keycloak: Exploiting the client registration API
Summary: CVE-2020-27838 keycloak: Exploiting the client registration API
Keywords:
Status: NEW
Alias: CVE-2020-27838
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1904057
TreeView+ depends on / blocked
 
Reported: 2020-12-11 12:26 UTC by Paramvir jindal
Modified: 2025-02-04 08:28 UTC (History)
27 users (show)

See Also:
Fixed In Version: keycloak 13.0.0
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Paramvir jindal 2020-12-11 12:26:34 UTC
Client registration endpoints should not allow fetching information about public clients without authentication.
https://issues.redhat.com/browse/KEYCLOAK-16521

Comment 4 Paramvir jindal 2021-02-19 14:12:00 UTC
Acknowledgments:

Name: Adam Devoe (SemaTree Inc.)

Comment 20 Patrick Del Bello 2024-02-01 19:12:25 UTC
According to the Jira issue this was fixed in RHSSO 7.5.0


Note You need to log in before you can comment on or make changes to this bug.