Information disclosure in Keycloak - CVE-2018-10894
Published: November 13, 2018 / Updated: November 23, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to SAML authentication incorrectly authenticated expired certificates. A remote attacker can supply specially crafted certificates and gain access to potentially sensitive information.
Affected software
Red Hat Single Sign-On