Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rxp-2rhr-qwqv

Опубликовано: 14 окт. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Keycloak has session fixation in Elytron SAML adapters

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 22.0.11

22.0.12

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 23.0.0, <= 24.0.6

24.0.7

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 25.0.0, < 25.0.5

25.0.5

EPSS

Процентиль: 78%
0.01149
Низкий

7.1 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 7.1
redhat
больше 1 года назад

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

CVSS3: 7.1
nvd
больше 1 года назад

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

CVSS3: 7.1
debian
больше 1 года назад

A session fixation issue was discovered in the SAML adapters provided ...

EPSS

Процентиль: 78%
0.01149
Низкий

7.1 High

CVSS3

Дефекты

CWE-384