PT-2017-12374 · Red Hat · Keycloak

Published

2017-10-26

·

Updated

2026-05-18

·

CVE-2017-12159

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak's CSRF prevention mechanism, where the cookie used was not unique to each session. This could allow an attacker to gain access to an authenticated user's session, potentially leading to information disclosure or further attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-FA60324
CLEANSTART-2026-GX01236
CLEANSTART-2026-KC06018
CLEANSTART-2026-PO27799
CLEANSTART-2026-SG80587
CVE-2017-12159
GHSA-7FMW-85QM-H22P
RHSA-2017:2904
RHSA-2017:2905

Affected Products

Keycloak