Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python312Packages.python-keycloak

Found 31 matching suggestions

Untriaged
created 5 months ago
Plaintext storage of user password

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with minimal access to retrieve the users passwords in clear text, jeopardizing their environment.

Affected products

keycloak
  • ==22.0.3

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

  • nixos-unstable -

Package maintainers