{"id":"GHSA-89c9-3758-737w","summary":"keycloak-httpd-client-install Insecure Secrets","details":"keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.","aliases":["CVE-2017-15112","PYSEC-2026-828"],"modified":"2026-07-07T11:56:42.076174222Z","published":"2022-05-14T00:55:07Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-26T20:18:53Z","nvd_published_at":"2018-01-20T00:29:00Z","cwe_ids":["CWE-200"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15112"},{"type":"WEB","url":"https://github.com/jdennis/keycloak-httpd-client-install/commit/c3121b271abaaa1a76de2b9ae89dacde0105cd75"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2137"},{"type":"PACKAGE","url":"https://github.com/jdennis/keycloak-httpd-client-install"}],"affected":[{"package":{"name":"keycloak-httpd-client-install","ecosystem":"PyPI","purl":"pkg:pypi/keycloak-httpd-client-install"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-89c9-3758-737w/GHSA-89c9-3758-737w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}