Related Vulnerabilities: CVE-2021-20202  

A security issue was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory.

Severity Medium

Remote No

Type Information disclosure

Description

A security issue was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory.

AVG-1332 keycloak 12.0.4-1 High Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1922128
https://issues.redhat.com/browse/KEYCLOAK-17000
https://github.com/keycloak/keycloak/pull/7859
https://github.com/keycloak/keycloak/commit/853a6d73276849877819f2dc23133557f6e1e601