PT-2025-43516 · Red Hat · Keycloak
Alexander Schwartz
·
Published
2025-10-23
·
Updated
2025-12-19
·
CVE-2025-11429
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A logic flaw exists in Keycloak’s session management. The software does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active maintain their extended session lifetime until they expire, bypassing the administrator’s recent security configuration change. This flaw stems from the session expiration logic relying on the session-local "remember-me" flag without verifying the current realm-level configuration. This increases the potential for session hijacking or unauthorized long-term access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak