CVE-2018-14637
published 2018-11-30CVE-2018-14637: The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this…
PriorityP343high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
0.81%
52.9th percentile
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 4.6.0 | 4.6.0 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Authentication in Keycloak
ghsa·2018-12-21
CVE-2018-14637 [HIGH] CWE-285 Improper Authentication in Keycloak
Improper Authentication in Keycloak
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
OSV
Improper Authentication in Keycloak
osv·2018-12-21
CVE-2018-14637 [HIGH] Improper Authentication in Keycloak
Improper Authentication in Keycloak
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Red Hat
keycloak: expiration not validated in SAML broker consumer endpoint
vendor_redhat·2018-11-27·CVSS 6.1
CVE-2018-14637 [MEDIUM] CWE-613 keycloak: expiration not validated in SAML broker consumer endpoint
keycloak: expiration not validated in SAML broker consumer endpoint
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
No detection rules found.
No public exploits indexed.
2018-11-30
Published