logo

Keycloak Security Update Advisory (CVE-2024-8698)

ID: 50233ab2-1a74-510f-bfa9-d2b6ba18528d

STIX ID: report--50233ab2-1a74-510f-bfa9-d2b6ba18528d

Feed Name: ASEC

Threat Score
65/100

Date Published: 2024-09-23

Date Updated: 2026-04-26

Author: ATCP

...
...

**Keycloak SAML signature validation vulnerability (CVE-2024-8698)** — An update addresses a flaw in Keycloak's XMLSignatureUtil SAML signature validation that could allow crafted responses to bypass validation, potentially leading to privilege escalation or impersonation; users of affected versions are advised to upgrade to the patched release. References: NVD and GitHub advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.