Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Maven

Improper Authentication in Keycloak

GHSA-gf2j-7qwg-4f5x · CVE-2018-14637

Published · Modified

Description

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

Ready to move

Start Securing

Free, no credit card | First findings in minutes