{"id":"PYSEC-2026-828","summary":"keycloak-httpd-client-install Insecure Secrets","details":"keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.","aliases":["CVE-2017-15112","GHSA-89c9-3758-737w"],"modified":"2026-07-07T11:46:04.489743140Z","published":"2026-07-06T08:03:21.520515Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15112"},{"type":"WEB","url":"https://github.com/jdennis/keycloak-httpd-client-install/commit/c3121b271abaaa1a76de2b9ae89dacde0105cd75"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2137"},{"type":"PACKAGE","url":"https://github.com/jdennis/keycloak-httpd-client-install"},{"type":"PACKAGE","url":"https://pypi.org/project/keycloak-httpd-client-install"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-89c9-3758-737w"}],"affected":[{"package":{"name":"keycloak-httpd-client-install","ecosystem":"PyPI","purl":"pkg:pypi/keycloak-httpd-client-install"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/keycloak-httpd-client-install/PYSEC-2026-828.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}