PT-2024-2167 · Red Hat · Keycloak

Mauro Matteo Cascella

·

Published

2024-02-21

·

Updated

2024-07-03

·

CVE-2023-6787

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description The issue is related to a flaw in the re-authentication mechanism within Keycloak, specifically in the org.keycloak.authentication module. This flaw allows an attacker to hijack an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login", prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login", an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Improper Authentication

Session Fixation

Weakness Enumeration

Related Identifiers

BDU:2024-02081
CVE-2023-6787
GHSA-C9H6-V78W-52WJ

Affected Products

Keycloak