QID 981087
QID 981087: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-gf2j-7qwg-4f5x)
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gf2j-7qwg-4f5x for updates pertaining to this vulnerability.
Vendor References
- GHSA-gf2j-7qwg-4f5x -
github.com/advisories/GHSA-gf2j-7qwg-4f5x
CVEs related to QID 981087
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gf2j-7qwg-4f5x | org.keycloak:keycloak-core |
|