S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Network Vulnerabilities·Updated Oct 18, 2024

CVE-2024-8698 Scanner

CVE-2024-8698 Scanner - Privilege Escalation vulnerability in Keycloak

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8698
7.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
AFFECTED< 25.0.5SAFE ✓≥ 25.0.5
Red Hat Build of Keycloakby Red Hat
Red Hat Build of Keycloakby Red Hat
Red Hat build of Keycloak 22by Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Aug 22, 2026View on NVD →
Detail

Keycloak is an open-source identity and access management solution released by Red Hat, Inc. It is widely adopted by organizations for its ability to secure applications and services with minimal fuss. Companies rely on Keycloak for single sign-on capabilities, social login functionalities, and user identity brokering across various platforms. In addition to its authentication roles, Keycloak manages user sessions, allowing seamless and secure access across enterprise applications. The software is frequently integrated with systems supporting SAML, OpenID Connect, and OAuth 2.0 protocols. Its versatility extends to hybrid cloud environments and on-premises deployments.

The vulnerability in question affects the SAML Core Package in Keycloak, particularly involving its signature validation mechanism. Due to improper validation logic within the XMLSignatureUtil class, attackers can modify the SAML signature to bypass standard validation checks. This flaw undermines the system's ability to correctly validate document or assertion signatures, leading to security gaps. Authenticity is compromised when the reference elements validating the signed data are overlooked. Malicious actors can exploit this character flaw to insert crafted responses that subvert authentication. In turn, privilege escalation and unauthorized impersonation attacks become feasible, threatening data integrity and access control measures.

The technical execution of this vulnerability centers around the SAML signature's placement within XML documents. The validation process improperly assumes authenticity based on location rather than reference elements. Attack vectors involve removing or repositioning XML signature elements to exploit this flaw in validation logic. The vulnerability is catered to both Header and Assertion elements, allowing SAML responses to be manipulated post-validation. This scope includes the potential modification of claim attributes such as NameID and AttributeValue to match unrecognized users. Crafting responses with altered attributes paves the way for unauthorized access roles.

If successfully exploited, this vulnerability may lead to unauthorized access and privilege escalation within affected systems. Attackers could pose as legitimate users, gaining access to sensitive information or critical functionalities undeservedly. In multi-tenant environments, the ramifications include cross-domain access, potentially leading to extensive information exposure. Data leaks or unauthorized data manipulation are plausible outcomes, as altered permissions could facilitate access to administrative functions. The impacts of exploitation extend to reputational damage, legal repercussions, and financial losses for enterprises relying on vulnerable systems.

REFERENCES

Solution Advice
  • Upgrade Keycloak to a version where this vulnerability is patched.
  • Implement strict access controls and user monitoring to detect unusual activity, particularly with SAML responses.
  • Review and enforce robust SAML assertion validation mechanisms, ensuring proper reference checks.
  • Consider enhancing SAML logging to catch anomalies in the signature validation process.
  • Work closely with security teams to audit and assess the integrity of existing SAML configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.