Description
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Related Vulnerabilities
CVE-2020-7747 Vulnerability in npm package lightning-server
CVE-2023-24163 Vulnerability in maven package cn.hutool:hutool-all
CVE-2019-10346 Vulnerability in maven package org.jenkins-ci.plugins:embeddable-build-status
CVE-2021-21172 Vulnerability in npm package electron
CVE-2018-5158 Vulnerability in maven package org.webjars.npm:pdfjs-dist