Total vulnerabilities in the database
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
Software | From | Fixed in |
---|---|---|
redhat / keycloak | 3.4.3 | 3.4.3.x |
redhat / single_sign-on | 7.2 | 7.2.x |