Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvv8-8wh9-9fh2

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Keycloak Authentication Error

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Пакеты

Наименование

org.keycloak:keycloak-saml-adapter-core

maven
Затронутые версииВерсия исправления

< 4.4.0.Final

4.4.0.Final

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 4.4.0.Final

4.4.0.Final

EPSS

Процентиль: 17%
0.00054
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.4
redhat
около 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

CVSS3: 5.4
nvd
около 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

CVSS3: 5.4
debian
около 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrec ...

EPSS

Процентиль: 17%
0.00054
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-295