Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10894

Опубликовано: 09 июл. 2018
Источник: redhat
CVSS3: 5.4

Описание

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakWill not fix
Red Hat Mobile Application Platform 4keycloakOut of support scope
Red Hat OpenShift Application RuntimeskeycloakAffected
Red Hat Single Sign-On 7.2.5 zipserverFixedRHSA-2018:359513.11.2018
Red Hat Single Sign-On 7.2 for RHEL 6rh-sso7-keycloakFixedRHSA-2018:359213.11.2018
Red Hat Single Sign-On 7.2 for RHEL 7rh-sso7-keycloakFixedRHSA-2018:359313.11.2018
Text-Only RHOARFixedRHSA-2019:087724.04.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1599434keycloak: auth permitted with expired certs in SAML client

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

CVSS3: 5.4
debian
больше 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrec ...

CVSS3: 5.4
github
больше 3 лет назад

Keycloak Authentication Error

5.4 Medium

CVSS3

Уязвимость CVE-2018-10894