CVE-2017-15112: Keycloak-Httpd-Client-Install Project Keycloak-Httpd-Client-Install
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
Affected products
- Keycloak-Httpd-Client-Install Project Keycloak-Httpd-Client-Install: before 0.8 (fixed in 0.8)
Published 2018-01-20. Last modified 2026-06-17.