Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12636
HistoryJan 15, 2019 - 9:19 a.m.

Information Disclosure

2019-01-1509:19:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.002

Percentile

55.5%

keycloak-saml-core is vulnerable to sensitive information disclosure. The attack exists because SAML messages are being parsed by replacing the string to obtain the attribute values with the system property in StaxParserUtil class. Therefore, attacker can just parse the chosen system property name through the SAML request ID field and can get the response with system property value in InResponseTo filed .

EPSS

0.002

Percentile

55.5%