CVE-2018-10894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
01/08/2018
Last modified:
17/06/2026

Description

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*