CVE-2019-10201: Improper Authentication
(updated )
It was found that Keycloak’s SAML broker did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature>
sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
References
Code Behaviors & Features
Detect and mitigate CVE-2019-10201 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →