CVE-2018-14637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
30/11/2018
Last modified:
17/06/2026

Description

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* 4.6.0 (excluding)