Impact
The vulnerability occurs in the SAML metadata import function of Keycloak services used for identity brokering. When an identity provider’s metadata lacks the appropriate key‑usage attributes, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This flaw is a CWE‑347 Missing Parameter Value vulnerability that permits an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account that is identified by an external identifier known to the attacker.
Affected Systems
Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8 are affected. Version information is not specified in the current advisory.
Risk and Exploitability
A CVSS score of 7.4 indicates high severity; the EPSS score is not available and the vulnerability is not listed in CISA KEV. The flaw requires no authentication to exploit but it does require that an attacker can influence the import of SAML metadata—typically through privileged access to the broker configuration or by hosting a malicious metadata document. Once the vulnerability is triggered the attacker can create forged SAML responses that the system accepts, enabling unauthorized login to user accounts when the attacker knows the target’s external identifier.
OpenCVE Enrichment