CVE-2019-10201 Information
Feb 14, 2021
cve
Description
It was found that Keycloak’s SAML broker versions up to 6.0.1 did not verify missing message signatures. If an attacker modifies the SAML Response and removes the Signature sections the message is still accepted and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10201
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.1
Share on: