7.7

CVE-2024-8698

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttps://github.com/keycloak/keycloak
Paket keycloak
Default Statusunaffected
Version < 25.0.5
Version 0
Status affected
HerstellerRed Hat
Produkt Red Hat Build of Keycloak
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat Build of Keycloak
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 22
Default Statusaffected
Version < *
Version 22.0.13-1
Status unaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 22
Default Statusaffected
Version < *
Version 22-18
Status unaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 22
Default Statusaffected
Version < *
Version 22-21
Status unaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 24
Default Statusaffected
Version < *
Version 24.0.8-1
Status unaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 24
Default Statusaffected
Version < *
Version 24-17
Status unaffected
HerstellerRed Hat
Produkt Red Hat build of Keycloak 24
Default Statusaffected
Version < *
Version 24-17
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.33.0-1.redhat_00015.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 1:2.0.0-2.redhat_00005.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.8.0-2.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.2.0-2.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.16.1-2.redhat_00007.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.2.2-28.redhat_2.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.15.1-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.14.0-2.redhat_00006.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:4.0.5-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 1:2.0.0-2.redhat_00005.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.0.1-1.redhat_00002.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:0.1.0-2.redhat_00010.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.12.284-2.redhat_00002.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.2.5-2.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:800.4.0-1.GA_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.1.0-4.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:6.2.31-1.Final_redhat_00002.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:8.0.1-3.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:0.8.1-2.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.1.3-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.0.1-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:1.1.3-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.5.3-1.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:4.0.2-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:5.3.10-1.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.22.1-1.redhat_00002.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:6.0.3-1.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:9.37.3-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:9.6.0-1.redhat_00002.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.3.0-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.0.1-3.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.0.1-2.Final_redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:3.0.4-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:8.0.0-6.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.0.16-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:2.2.0-1.redhat_00001.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
Default Statusaffected
Version < *
Version 0:8.0.4-2.GA_redhat_00005.1.el8eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.33.0-1.redhat_00015.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 1:2.0.0-2.redhat_00005.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.8.0-2.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.2.0-2.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.16.1-2.redhat_00007.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.2.2-28.redhat_2.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.15.1-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.14.0-2.redhat_00006.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:4.0.5-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 1:2.0.0-2.redhat_00005.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.0.1-1.redhat_00002.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:0.1.0-2.redhat_00010.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.12.284-2.redhat_00002.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.2.5-2.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:800.4.0-1.GA_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.1.0-4.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:6.2.31-1.Final_redhat_00002.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:8.0.1-3.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:0.8.1-2.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.1.3-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.0.1-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:1.1.3-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.5.3-1.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:4.0.2-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:5.3.10-1.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.22.1-1.redhat_00002.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:6.0.3-1.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:9.37.3-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:9.6.0-1.redhat_00002.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.3.0-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.0.1-3.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.0.1-2.Final_redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:3.0.4-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:8.0.0-6.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.0.16-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:2.2.0-1.redhat_00001.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Default Statusaffected
Version < *
Version 0:8.0.4-2.GA_redhat_00005.1.el9eap
Status unaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7.6 for RHEL 7
Default Statusaffected
Version < *
Version 0:18.0.18-1.redhat_00001.1.el7sso
Status unaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7.6 for RHEL 8
Default Statusaffected
Version < *
Version 0:18.0.18-1.redhat_00001.1.el8sso
Status unaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7.6 for RHEL 9
Default Statusaffected
Version < *
Version 0:18.0.18-1.redhat_00001.1.el9sso
Status unaffected
HerstellerRed Hat
Produkt RHEL-8 based Middleware Containers
Default Statusaffected
Version < *
Version 7.6-54
Status unaffected
HerstellerRed Hat
Produkt Red Hat Build of Keycloak
Default Statusaffected
HerstellerRed Hat
Produkt Red Hat Single Sign-On 7
Default Statusaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 79.58% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secalert@redhat.com 7.7 1.8 5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.