VDB

CVE-2019-10201

CVE-2019-10201 PUBLISHED CVSS 8.1 HIGH

Reported by redhat · Published August 14, 2019

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

Risk Scores

CVSS 3.0
8.1
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatkeycloakup to keycloak 6.0.1
Red Hatkeycloakup to keycloak 6.0.1, *, up to keycloak 6.0.1
Mavenorg.keycloak:keycloak-core0, 0, 0
npmkeycloak-connect0, 0, 0

Timeline

  • Aug 14, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›