Keycloak Vulnerability Puts SAML Authentication at Risk

Sep 23, 2024

The vulnerability lies in Keycloak’s XMLSignatureUtil class, which incorrectly verifies SAML signatures, disregarding the vital “Reference” element that specifies the signed portion of the document.

Get Free Report & Network Analysis

Please check your email for the free report.