CVE-2023-6787
published 2024-04-25CVE-2023-6787: A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 22.0.10 | 22.0.10 |
| redhat | keycloak | >= 23.0.0 < 24.0.3 | 24.0.3 |