Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10894

Опубликовано: 09 июл. 2018
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakWill not fix
Red Hat Mobile Application Platform 4keycloakOut of support scope
Red Hat OpenShift Application RuntimeskeycloakAffected
Red Hat Single Sign-On 7.2.5 zipserverFixedRHSA-2018:359513.11.2018
Red Hat Single Sign-On 7.2 for RHEL 6rh-sso7-keycloakFixedRHSA-2018:359213.11.2018
Red Hat Single Sign-On 7.2 for RHEL 7rh-sso7-keycloakFixedRHSA-2018:359313.11.2018
Text-Only RHOARFixedRHSA-2019:087724.04.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1599434keycloak: auth permitted with expired certs in SAML client

EPSS

Процентиль: 17%
0.00054
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

CVSS3: 5.4
debian
около 7 лет назад

It was found that SAML authentication in Keycloak 3.4.3.Final incorrec ...

CVSS3: 5.4
github
больше 3 лет назад

Keycloak Authentication Error

EPSS

Процентиль: 17%
0.00054
Низкий

5.4 Medium

CVSS3