Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-8698 PoC — Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak

Source
Associated Vulnerability
Title:Keycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak (CVE-2024-8698)
Description:A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.
Description
i'm noob with saml and keycloak . J4f
Readme
https://huydoppa.hashnode.dev/analyst-cve-2024-8698-keycloak-with-zero-knowledge-about-keycloak
File Snapshot

[4.0K] /data/pocs/d240e3f334aa6208071238e9e558b28e417dd1b0 ├── [6.7M] poc.mp4 ├── [ 647] pom.xml ├── [ 96] README.md └── [4.0K] src └── [4.0K] main └── [4.0K] java └── [4.0K] test └── [7.0K] Main.java 4 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →