Keycloak Security Update Advisory (CVE-2024-8698)
ID: 50233ab2-1a74-510f-bfa9-d2b6ba18528d
STIX ID: report--50233ab2-1a74-510f-bfa9-d2b6ba18528d
Feed Name: ASEC
Threat Score
**Keycloak SAML signature validation vulnerability (CVE-2024-8698)** — An update addresses a flaw in Keycloak's XMLSignatureUtil SAML signature validation that could allow crafted responses to bypass validation, potentially leading to privilege escalation or impersonation; users of affected versions are advised to upgrade to the patched release. References: NVD and GitHub advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
