Related Vulnerabilities: CVE-2020-27838  

Client registration endpoints should not allow fetching information about public clients without authentication.

Severity Medium

Remote Yes

Type Information disclosure

Description

Client registration endpoints should not allow fetching information about public clients without authentication.

AVG-1332 keycloak 11.0.3-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1906797
https://issues.redhat.com/browse/KEYCLOAK-16521