Описание
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
Отчет
Red Hat JBoss EAP 8.x is not affected. The vulnerable components (picketlink-federation, picketlink-common) are not shipped in EAP 8.x. The org/picketlink/ module path does not exist. The only PicketLink-related artifact in EAP 8.1 is wildfly-picketlink-8.1.1.GA-redhat-00012.jar — a WildFly subsystem extension that provides the migrate CLI operation for EAP 7→8 upgrades. This JAR contains no SAML processing code, no signature validation logic, and has no module dependency on org.picketlink.federation. The PicketLink SAML SP code path is entirely absent from EAP 8.x.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | picketlink-federation | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | picketlink-federation | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7.4.25 | picketlink-federation | Fixed | RHSA-2026:53806 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-activemq-artemis | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-glassfish-jsf | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-ironjacamar | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-annotations | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-core | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-databind | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-jaxrs-providers | Fixed | RHSA-2026:53644 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
EPSS
8.1 High
CVSS3