Description
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Related Vulnerabilities
CVE-2023-50720 Vulnerability in maven package org.xwiki.platform:xwiki-platform-search-solr-api
CVE-2022-31160 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2018-14041 Vulnerability in maven package org.webjars:bootstrap
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2023-27900 Vulnerability in maven package org.jenkins-ci.main:jenkins-core