CVE-2024-8698

Scores

EPSS

0.813high81.3%
0%20%40%60%80%100%

Percentile: 81.3%

CVSS

7.7high3.x
0246810

CVSS Score: 7.7/10

All CVSS Scores

CVSS 3.x
7.7

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L

Description

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debianredhat

CWEs

CWE-347

Related Vulnerabilities

Exploits

Exploit ID: CVE-2024-8698

Source: github-poc

URL: https://github.com/huydoppaz/CVE-2024-8698-POC

Vulnerable Software (78)

Type: Configuration

Product: eap8-activemq-artemis

Operating System: rhel

Trait:
{  "fixed": "2.33.0-1.redhat_00015.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-activemq-artemis

Operating System: rhel

Trait:
{  "fixed": "2.33.0-1.redhat_00015.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-activemq-artemis-native

Operating System: rhel

Trait:
{  "fixed": "2.0.0-2.redhat_00005.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-activemq-artemis-native

Operating System: rhel

Trait:
{  "fixed": "2.0.0-2.redhat_00005.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-aesh-extensions

Operating System: rhel

Trait:
{  "fixed": "1.8.0-2.redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-aesh-extensions

Operating System: rhel

Trait:
{  "fixed": "1.8.0-2.redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-aesh-readline

Operating System: rhel

Trait:
{  "fixed": "2.2.0-2.redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-aesh-readline

Operating System: rhel

Trait:
{  "fixed": "2.2.0-2.redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-codec

Operating System: rhel

Trait:
{  "fixed": "1.16.1-2.redhat_00007.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-codec

Operating System: rhel

Trait:
{  "fixed": "1.16.1-2.redhat_00007.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-collections

Operating System: rhel

Trait:
{  "fixed": "3.2.2-28.redhat_2.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-collections

Operating System: rhel

Trait:
{  "fixed": "3.2.2-28.redhat_2.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-io

Operating System: rhel

Trait:
{  "fixed": "2.15.1-1.redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-io

Operating System: rhel

Trait:
{  "fixed": "2.15.1-1.redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-lang

Operating System: rhel

Trait:
{  "fixed": "3.14.0-2.redhat_00006.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-commons-lang

Operating System: rhel

Trait:
{  "fixed": "3.14.0-2.redhat_00006.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "4.0.5-1.redhat_00001.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-apache-cxf

Operating System: rhel

Trait:
{  "fixed": "4.0.5-1.redhat_00001.1.el9eap"}

Source: redhat

Type: Configuration

Product: eap8-artemis-native

Operating System: rhel

Trait:
{  "fixed": "2.0.0-2.redhat_00005.1.el8eap"}

Source: redhat

Type: Configuration

Product: eap8-artemis-native

Operating System: rhel

Trait:
{  "fixed": "2.0.0-2.redhat_00005.1.el9eap"}

Source: redhat