QID 982829
QID 982829: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-4fgq-gq9g-3rw7)
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4fgq-gq9g-3rw7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4fgq-gq9g-3rw7 -
github.com/advisories/GHSA-4fgq-gq9g-3rw7
CVEs related to QID 982829
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4fgq-gq9g-3rw7 | org.keycloak:keycloak-core |
|