Skip to main content

Threats Tagged 'cve-2024-8698'

View all threats tagged with 'cve-2024-8698'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-8698

Threats Tagged 'cve-2024-8698'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat has released updated container images for the Red Hat build of Keycloak 24.0.8 to address two security vulnerabilities. The first vulnerability (CVE-2024-8698) involves improper verification of SAML responses that could lead to privilege escalation. The second vulnerability (CVE-2024-8883) concerns vulnerable redirect URI validation resulting in an open redirect issue. These updates are intended for use within the OpenShift Container Platform for on-premise or private cloud deployments. The advisory recommends backing up existing installations before applying the update. No known exploits in the wild have been reported at this time.

Join the discussion

Red Hat has released an important security advisory for the Red Hat build of Keycloak 24.0.8 addressing two vulnerabilities: CVE-2024-8698, which involves improper verification of SAML responses that can lead to privilege escalation, and CVE-2024-8883, which concerns vulnerable redirect URI validation resulting in open redirect issues. These vulnerabilities affect the authentication and single sign-on capabilities of Keycloak. The advisory recommends updating to the fixed version 24.0.8 and backing up existing installations before applying the update.

Join the discussion

Red Hat has released updated images for the Red Hat build of Keycloak 22.0.13 addressing two security vulnerabilities. The first vulnerability (CVE-2024-8698) involves improper verification of SAML responses that could lead to privilege escalation. The second vulnerability (CVE-2024-8883) concerns vulnerable redirect URI validation resulting in an open redirect issue. These updates are intended for use within the OpenShift Container Platform for on-premise or private cloud deployments. The advisory recommends backing up existing installations before applying the update.

Join the discussion

Red Hat has released an important security update for Red Hat build of Keycloak 22.0.13, addressing two vulnerabilities: CVE-2024-8698, an improper verification of SAML responses that can lead to privilege escalation, and CVE-2024-8883, a vulnerable redirect URI validation resulting in an open redirect issue. These vulnerabilities affect authentication and single sign-on capabilities provided by Keycloak. The update replaces Red Hat Single Sign-On 7.6 and includes bug fixes and enhancements. Users are advised to back up their installations before applying the update.

Join the discussion

Red Hat Single Sign-On 7.6.11 addresses two security vulnerabilities in the Keycloak-based authentication server. The first vulnerability (CVE-2024-8698) involves improper verification of SAML responses that could lead to privilege escalation. The second vulnerability (CVE-2024-8883) concerns vulnerable redirect URI validation resulting in an open redirect issue. These vulnerabilities have been rated with an important security impact by Red Hat. The update replaces version 7.6.10 and includes bug fixes and enhancements. Users are advised to back up their installations before applying the update.

Join the discussion

Red Hat Single Sign-On 7.6.11 for OpenShift contains two security vulnerabilities: improper verification of SAML responses leading to privilege escalation (CVE-2024-8698) and vulnerable redirect URI validation resulting in an open redirect (CVE-2024-8883). These issues affect the authentication server component used for centralized login and user management in OpenShift containerized environments. Red Hat has released an updated image to address these vulnerabilities for OpenShift Container Platform versions 3.10, 3.11, and 4.3. The update aligns with the standalone product release and is intended for on-premise or private cloud deployments. No known exploits in the wild have been reported.

Join the discussion

Red Hat Single Sign-On 7.6.11 for RHEL 9 addresses two security vulnerabilities: improper verification of SAML responses that could lead to privilege escalation (CVE-2024-8698) and vulnerable redirect URI validation resulting in open redirect issues (CVE-2024-8883). These vulnerabilities affect authentication and authorization mechanisms in the Keycloak-based SSO server. Red Hat has released this update to fix these issues and recommends applying it after ensuring all prior errata are installed. No known exploits in the wild have been reported at this time.

Join the discussion

Red Hat Single Sign-On 7.6.11 for RHEL 8 addresses two security vulnerabilities: an improper verification of SAML responses that could lead to privilege escalation (CVE-2024-8698) and a vulnerable redirect URI validation resulting in an open redirect (CVE-2024-8883). These issues affect the authentication and single sign-on capabilities provided by the product. Red Hat has released this update as a replacement for version 7.6.10, including bug fixes and enhancements. The vendor rates the security impact of this update as none, indicating no direct impact on Red Hat's assessment, but the vulnerabilities themselves are classified as high severity. No explicit CVSS scores are provided in the advisory. Users are advised to apply this update after ensuring all previous errata are applied.

Join the discussion

Red Hat Single Sign-On 7.6.11 for RHEL 7 addresses two security vulnerabilities: an improper verification of SAML responses that could lead to privilege escalation (CVE-2024-8698) and a vulnerable redirect URI validation resulting in an open redirect (CVE-2024-8883). These issues were fixed in this update, which replaces version 7.6.10. Red Hat has rated the update as important and classified the security impact as none in their advisory, but the vulnerabilities themselves are considered high severity. No CVSS scores are provided in the advisory. The update includes bug fixes and enhancements documented in the release notes. Users should apply this update after ensuring all prior relevant errata are installed.

Join the discussion

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cve-2024-8698
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses