Description
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Related Vulnerabilities
CVE-2020-10721 Vulnerability in maven package io.fabric8:fabric8-maven-plugin-core
CVE-2023-30532 Vulnerability in maven package org.jenkinsci.plugins.spoonscript:spoonscript
CVE-2020-8203 Vulnerability in npm package @sailshq/lodash
CVE-2020-1698 Vulnerability in maven package org.keycloak:keycloak-authz-client
CVE-2019-10169 Vulnerability in maven package org.keycloak:keycloak-authz-client