CVE-2017-15112: Keycloak-Httpd-Client-Install Project Keycloak-Httpd-Client-Install

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.

Affected products

Published 2018-01-20. Last modified 2026-06-17.