Description
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Related Vulnerabilities
CVE-2017-1000491 Vulnerability in npm package shiba
CVE-2022-25209 Vulnerability in maven package org.jenkins-ci.plugins:sinatra-chef-builder
CVE-2022-0341 Vulnerability in npm package vditor
CVE-2019-10157 Vulnerability in npm package keycloak-connect
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo