Описание
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
Ссылки
- Issue TrackingMitigationVendor Advisory
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8.1 High
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
Связанные уязвимости
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
It was found that Keycloak's SAML broker, versions up to 6.0.1, did no ...
Improper Verification of Cryptographic Signature in keycloak
Уязвимость компонента SAML broker программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к системе
EPSS
8.1 High
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2