It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-08-01T17:00:00

Updated: 2019-04-24T21:06:04

Reserved: 2018-05-09T00:00:00


Link: CVE-2018-10894

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-08-01T17:29:00.347

Modified: 2019-10-09T23:33:10.180


Link: CVE-2018-10894

JSON object: View

cve-icon Redhat Information

No data.