CVE-2018-14637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/11/2018
Last modified:
09/10/2019

Description

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* 4.6.0 (excluding)


References to Advisories, Solutions, and Tools