HIGH🇬🇧 English

CVE-2019-10201

CVSS 8.1v3.1pub. 2019-08-14upd. 2024-11-21

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Red Hat Keycloak

    APP
    Redhat
    ≤ 6.0.1
  • Red Hat Single Sign On

    APP
    Redhat
    7.07.3.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-12543CRITICAL9.6PL ✓ten sam produkt

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2022-4361CRITICAL10.0PL ✓ten sam produkt

XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów

CVE-2022-3782CRITICAL9.1PL ✓ten sam produkt

Keycloak: path traversal przez podwójne kodowanie URL w przekierowaniach

CVE-2022-1245CRITICAL9.8PL ✓ten sam produkt

Privilege escalation w mechanizmie token exchange w Keycloak

CVE-2021-20195CRITICAL9.6PL ✓ten sam produkt

Stored XSS umożliwiający przejęcie konta w Keycloak