CVE-2018-10894Insufficient Verification of Data Authenticity in RED HAT Keycloak

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 82.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 13

Description

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages3 packages

NVDredhat/keycloak3.4.3
CVEListV5red_hat/keycloak3.4.3.Final

Patches

🔴Vulnerability Details

3
OSV
Keycloak Authentication Error2022-05-13
GHSA
Keycloak Authentication Error2022-05-13
CVEList
CVE-2018-10894: It was found that SAML authentication in Keycloak 32018-08-01

📋Vendor Advisories

1
Red Hat
keycloak: auth permitted with expired certs in SAML client2018-07-09

💬Community

2
Bugzilla
CVE-2018-8027 camel-core: XXE in XSD validation processor2018-08-02
Bugzilla
CVE-2018-10894 keycloak: auth permitted with expired certs in SAML client2018-07-09
CVE-2018-10894 — RED HAT Keycloak vulnerability | cvebase