Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6787

Опубликовано: 25 апр. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
Версия до 22.0.10 (исключая)
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
Версия от 23.0.0 (включая) до 24.0.3 (исключая)

EPSS

Процентиль: 59%
0.00385
Низкий

6.5 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 6.5
redhat
почти 2 года назад

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

CVSS3: 6.5
debian
почти 2 года назад

A flaw was found in Keycloak that occurs from an error in the re-authe ...

CVSS3: 6.5
github
почти 2 года назад

Keycloak vulnerable to session hijacking via re-authentication

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с недостатками процедуры аутентификации, позволяющая нарушителю перехватить активный сеанс

EPSS

Процентиль: 59%
0.00385
Низкий

6.5 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-287
CWE-287