Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9h6-v78w-52wj

Опубликовано: 17 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Keycloak vulnerable to session hijacking via re-authentication

A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 22.0.10

22.0.10

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 23.0.0, < 24.0.3

24.0.3

EPSS

Процентиль: 59%
0.00385
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-384
CWE-613

Связанные уязвимости

CVSS3: 6.5
redhat
почти 2 года назад

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

CVSS3: 6.5
nvd
почти 2 года назад

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

CVSS3: 6.5
debian
почти 2 года назад

A flaw was found in Keycloak that occurs from an error in the re-authe ...

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с недостатками процедуры аутентификации, позволяющая нарушителю перехватить активный сеанс

EPSS

Процентиль: 59%
0.00385
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-384
CWE-613