7.7
CVE-2024-8698
- EPSS 79.58%
- Published 19.09.2024 16:15:06
- Last modified 12.12.2024 20:15:22
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://github.com/keycloak/keycloak
≫
Package
keycloak
Default Statusunaffected
Version <
25.0.5
Version
0
Status
affected
VendorRed Hat
≫
Product
Red Hat Build of Keycloak
Default Statusunaffected
VendorRed Hat
≫
Product
Red Hat Build of Keycloak
Default Statusunaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 22
Default Statusaffected
Version <
*
Version
22.0.13-1
Status
unaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 22
Default Statusaffected
Version <
*
Version
22-18
Status
unaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 22
Default Statusaffected
Version <
*
Version
22-21
Status
unaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 24
Default Statusaffected
Version <
*
Version
24.0.8-1
Status
unaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 24
Default Statusaffected
Version <
*
Version
24-17
Status
unaffected
VendorRed Hat
≫
Product
Red Hat build of Keycloak 24
Default Statusaffected
Version <
*
Version
24-17
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.33.0-1.redhat_00015.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
1:2.0.0-2.redhat_00005.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.8.0-2.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.2.0-2.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.16.1-2.redhat_00007.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.2.2-28.redhat_2.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.15.1-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.14.0-2.redhat_00006.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:4.0.5-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
1:2.0.0-2.redhat_00005.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.0.1-1.redhat_00002.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:0.1.0-2.redhat_00010.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.12.284-2.redhat_00002.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.2.5-2.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:800.4.0-1.GA_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.1.0-4.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:6.2.31-1.Final_redhat_00002.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:8.0.1-3.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:0.8.1-2.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.1.3-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.0.1-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:1.1.3-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.5.3-1.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:4.0.2-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:5.3.10-1.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.22.1-1.redhat_00002.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:6.0.3-1.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:9.37.3-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:9.6.0-1.redhat_00002.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.3.0-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.0.1-3.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.0.1-2.Final_redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:3.0.4-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:8.0.0-6.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.0.16-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:2.2.0-1.redhat_00001.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version <
*
Version
0:8.0.4-2.GA_redhat_00005.1.el8eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.33.0-1.redhat_00015.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
1:2.0.0-2.redhat_00005.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.8.0-2.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.2.0-2.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.16.1-2.redhat_00007.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.2.2-28.redhat_2.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.15.1-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.14.0-2.redhat_00006.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:4.0.5-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
1:2.0.0-2.redhat_00005.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.0.1-1.redhat_00002.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:0.1.0-2.redhat_00010.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.12.284-2.redhat_00002.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.2.5-2.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:800.4.0-1.GA_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.1.0-4.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:6.2.31-1.Final_redhat_00002.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:8.0.1-3.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:0.8.1-2.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.1.3-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.0.1-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:1.1.3-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.5.3-1.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:4.0.2-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:5.3.10-1.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.22.1-1.redhat_00002.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:6.0.3-1.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:9.37.3-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:9.6.0-1.redhat_00002.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.3.0-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.0.1-3.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.0.1-2.Final_redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:3.0.4-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:8.0.0-6.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.0.16-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:2.2.0-1.redhat_00001.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version <
*
Version
0:8.0.4-2.GA_redhat_00005.1.el9eap
Status
unaffected
VendorRed Hat
≫
Product
Red Hat Single Sign-On 7
Default Statusunaffected
VendorRed Hat
≫
Product
Red Hat Single Sign-On 7.6 for RHEL 7
Default Statusaffected
Version <
*
Version
0:18.0.18-1.redhat_00001.1.el7sso
Status
unaffected
VendorRed Hat
≫
Product
Red Hat Single Sign-On 7.6 for RHEL 8
Default Statusaffected
Version <
*
Version
0:18.0.18-1.redhat_00001.1.el8sso
Status
unaffected
VendorRed Hat
≫
Product
Red Hat Single Sign-On 7.6 for RHEL 9
Default Statusaffected
Version <
*
Version
0:18.0.18-1.redhat_00001.1.el9sso
Status
unaffected
VendorRed Hat
≫
Product
RHEL-8 based Middleware Containers
Default Statusaffected
Version <
*
Version
7.6-54
Status
unaffected
VendorRed Hat
≫
Product
Red Hat Build of Keycloak
Default Statusaffected
VendorRed Hat
≫
Product
Red Hat Single Sign-On 7
Default Statusaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 79.58% | 0.99 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secalert@redhat.com | 7.7 | 1.8 | 5.3 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.