Lucene search

K
osvGoogleOSV:CVE-2019-10201
HistoryAug 14, 2019 - 5:15 p.m.

CVE-2019-10201

2019-08-1417:15:11
Google
osv.dev
9

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

28.4%

It was found that Keycloak’s SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

28.4%