Fedora Account System
Red Hat Associate
Red Hat Customer
initial report doc: https://docs.google.com/document/d/1Rf4NtLudECimDNy8F9clUblm6Avx8_yF/edit relevant section info: XML Signature Wrapping — PicketLink SP signedAssertions==0 short-circuit (SAML 2.0 auth bypass) (JBoss EAP) SAML 2.0 authentication bypass: PicketLink's SP signature-validation logic short-circuits when the SAML Response contains zero Assertion elements matching the signature check (e.g. the signed assertion is moved outside the validated subtree via XML Signature Wrapping), allowing an attacker to forge a SAML Response and authenticate as any principal with any roles on the protected application. findings/jboss-eap_30.md
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4.25 Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806