Red Hat Bugzilla – Bug 1599434
CVE-2018-10894 keycloak: auth permitted with expired certs in SAML client
Last modified: 2018-09-19 18:14:01 EDT
It was found that SAML authentication in Keycloak incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
Acknowledgments: Name: Benjamin Berg (Red Hat)
upstream patch: https://issues.jboss.org/secure/attachment/12439846/0001-KEYCLOAK-8163-Improve-SAML-validations.patch attached to jira: https://issues.jboss.org/browse/KEYCLOAK-8163