Описание
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.6.0 (исключая)
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00252
Низкий
6.1 Medium
CVSS3
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-285
CWE-287
Связанные уязвимости
CVSS3: 6.1
redhat
около 7 лет назад
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
CVSS3: 6.1
debian
около 7 лет назад
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Fin ...
EPSS
Процентиль: 48%
0.00252
Низкий
6.1 Medium
CVSS3
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-285
CWE-287