An information disclosure vulnerability exists in the...
Moderate severity
Unreviewed
Published
Dec 23, 2023
to the GitHub Advisory Database
•
Updated Dec 23, 2023
Description
Published by the National Vulnerability Database
Dec 23, 2023
Published to the GitHub Advisory Database
Dec 23, 2023
Last updated
Dec 23, 2023
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
References