CVE-2018-10894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
01/08/2018
Last modified:
09/10/2019

Description

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*