Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fgq-gq9g-3rw7

Опубликовано: 23 сент. 2019
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Improper Verification of Cryptographic Signature in keycloak

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

<= 6.0.1

7.0.0

EPSS

Процентиль: 34%
0.00136
Низкий

8.1 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 8.1
redhat
больше 6 лет назад

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

CVSS3: 8.1
nvd
больше 6 лет назад

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

CVSS3: 8.1
debian
больше 6 лет назад

It was found that Keycloak's SAML broker, versions up to 6.0.1, did no ...

CVSS3: 8.1
fstec
больше 6 лет назад

Уязвимость компонента SAML broker программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к системе

EPSS

Процентиль: 34%
0.00136
Низкий

8.1 High

CVSS3

Дефекты

CWE-347