CVE-2018-10894
01.08.2018, 17:29
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | keycloak | 3.4.3 |
redhat | single_sign-on | 7.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References