CVE-2024-8698
Aliases:GHSA-xgfv-xpx8-qhcr
Advisory lineage Upstream: 0 Downstream: 5
Deferred
Published: 19 Sept 2024, 15:48
Last modified:01 Apr 2026, 11:23
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.7 HIGH
v3.1 (cve.org)
EPSS Score
2.03% LOW
2% probability -77.13%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
19 Sept 2024, 15:48
Published
Vulnerability first disclosed
01 Apr 2026, 11:23
Last Modified
Vulnerability information updated
Description
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.
CVSS Metrics
- v3.1•HIGH•Score: 7.7CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
EPSS Trends
Current EPSS score: 2.03%• Percentile: 79%
Techniques & Countermeasures
- CWE-347•Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Affected Systems
- org.keycloak•keycloak-saml-core
< 22.0.13 | ≥ 23.0.0, < 24.0.8 | ≥ 25.0.0, < 25.0.6
References (18)
- https://access.redhat.com/errata/RHSA-2024:6878
- https://access.redhat.com/errata/RHSA-2024:6879
- https://access.redhat.com/errata/RHSA-2024:6880
- https://access.redhat.com/errata/RHSA-2024:6882
- https://access.redhat.com/errata/RHSA-2024:6886
- https://access.redhat.com/errata/RHSA-2024:6887
- https://access.redhat.com/errata/RHSA-2024:6888
- https://access.redhat.com/errata/RHSA-2024:6889
- https://access.redhat.com/errata/RHSA-2024:6890
- https://access.redhat.com/errata/RHSA-2024:8823
- https://access.redhat.com/errata/RHSA-2024:8824
- https://access.redhat.com/errata/RHSA-2024:8826
- https://access.redhat.com/security/cve/CVE-2024-8698
- https://bugzilla.redhat.com/show_bug.cgi?id=2311641
- https://github.com/keycloak/keycloak/security/advisories/GHSA-xgfv-xpx8-qhcr
- https://nvd.nist.gov/vuln/detail/CVE-2024-8698
- https://github.com/keycloak/keycloak/releases/tag/25.0.6
- https://github.com/keycloak/keycloak