CVE-2018-10894

Related Vulnerabilities: CVE-2018-10894  

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

The MITRE CVE dictionary describes this issue as:

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Find out more about CVE-2018-10894 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 5.4
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Single Sign-On 7.1 for RHEL 7 Server (rh-sso7-keycloak) RHSA-2018:3593 2018-11-13
Red Hat Single Sign-On 7.2 RHSA-2018:3595 2018-11-13
Red Hat Single Sign-On 7.1 for RHEL 6 Server (rh-sso7-keycloak) RHSA-2018:3592 2018-11-13

Affected Packages State

Platform Package State
Red Hat Single Sign-On 7 server Affected

Acknowledgements

This issue was discovered by Benjamin Berg (Red Hat).