If an attacker modifies the SAML Response and removes the <Signature> Sections, the message is still accepted and the message can be modified, allowing the attacker to impersonate any user on the keycloak protected systems by modifying assertations.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-10786