Description
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Related Vulnerabilities
CVE-2021-21162 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-17534 Vulnerability in maven package org.netbeans.html:webkit
CVE-2023-28674 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap