Description
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14637
Related Vulnerabilities
CVE-2019-12041 Vulnerability in maven package org.webjars.bower:remarkable
CVE-2019-15600 Vulnerability in npm package http_server
CVE-2019-1003099 Vulnerability in maven package org.jenkins-ci.plugins:openid
CVE-2019-19899 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source