[MAVEN:GHSA-XVV8-8WH9-9FH2] Keycloak Authentication Error

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

ID
MAVEN:GHSA-XVV8-8WH9-9FH2
Severity
moderate
URL
https://github.com/advisories/GHSA-xvv8-8wh9-9fh2
Published
2022-05-13T01:34:55
(2 years ago)
Modified
2023-10-06T17:25:02
(11 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 4.4.0.Final
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 4.4.0.Final
Affected pkg:maven/org.keycloak/keycloak-saml-adapter-core org.keycloak keycloak-saml-adapter-core < 4.4.0.Final
Fixed pkg:maven/org.keycloak/keycloak-saml-adapter-core org.keycloak keycloak-saml-adapter-core = 4.4.0.Final
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...