CVE-2018-14637: High severity red hat keycloak vulnerability
A flaw was found in JBOSS Keycloak. The SAML broker consumer endpoint ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
Other sources
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14637?
CVE-2018-14637 has been classified with a high severity due to its potential for replay attacks.
How do I fix CVE-2018-14637?
To resolve CVE-2018-14637, upgrade Keycloak to version 4.6.0.Final or later.
What specific systems are affected by CVE-2018-14637?
CVE-2018-14637 affects Keycloak versions prior to 4.6.0.Final.
What type of attack can CVE-2018-14637 facilitate?
CVE-2018-14637 can facilitate replay attacks due to the ignoring of expiration conditions on SAML assertions.
Is there a workaround for CVE-2018-14637?
There is no known workaround for CVE-2018-14637; upgrading to the patched version is the recommended approach.