CVE-2018-10894

CVSS v3.0 5.4 (Medium)
54% Progress
CVSS v2.0 5.5 (Medium)
55% Progress
EPSS 0.09 % (38th)
0.09% Progress
Affected Products 3
Advisories 1

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Weaknesses
CWE-295
Improper Certificate Validation
CWE-345
Insufficient Verification of Data Authenticity
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2018-08-01 17:29:00
(6 years ago)
Updated Date
2019-10-09 23:33:10
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Redhat Keycloak 3.4.3 cpe:2.3:a:redhat:keycloak:3.4.3

Configuration #2

AND
    CPE23 From Up To
OR  
  Redhat Single Sign-on 7.2 cpe:2.3:a:redhat:single_sign-on:7.2
OR  
  Running on/with
  Redhat Enterprise Linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0
OR  
  Running on/with
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...