PT-2025-43516 · Red Hat · Keycloak

Alexander Schwartz

·

Published

2025-10-23

·

Updated

2025-12-19

·

CVE-2025-11429

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A logic flaw exists in Keycloak’s session management. The software does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active maintain their extended session lifetime until they expire, bypassing the administrator’s recent security configuration change. This flaw stems from the session expiration logic relying on the session-local "remember-me" flag without verifying the current realm-level configuration. This increases the potential for session hijacking or unauthorized long-term access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11429
ECHO-0DB4-A794-6040
GHSA-64W3-5Q9M-68XF

Affected Products

Keycloak