Symptoms
Using the wrong syntax in the login request payload reflects the whole request payload in the response, which may contain the original password from the request in clear text.
Impact
Request Password is shown in cleartext
Conditions
Using "loginReference" instead of "loginProviderName" in the login request