Improper Authentication in Keycloak - CVE-2019-10201
Published: August 27, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the Security Assertion Markup Language (SAML) broker does not properly parse messages. A remote attacker can send a specially crafted SAML request, bypass authentication process and gain unauthorized access to the application.
Affected software
Red Hat Single Sign-On
Opensuse
How to mitigate CVE-2019-10201
Red Hat Single Sign-On - update to 7.3.3