Описание
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
Отчет
Important: A flaw in Keycloak's cross-session email verification allows an attacker to gain persistent access to a victim's local account. This occurs when an attacker controls an upstream identity provider account sharing an email with the victim, and the victim is actively linking their account while email verification is enabled and the identity provider is configured with trustEmail=false. The attacker can then consume the verification proof, linking their account to the victim's.
Меры по смягчению последствий
To mitigate this issue, configure the affected identity provider to set trustEmail=true. This ensures that Keycloak trusts the email address provided by the upstream identity provider, bypassing the vulnerable verification flow. This mitigation should only be applied if the upstream identity provider is fully trusted to verify email addresses and prevent malicious account creation with existing email addresses. Configuration changes may require a Keycloak service restart or reload to take effect.
Дополнительная информация
Статус:
6.4 Medium
CVSS3
Связанные уязвимости
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
A flaw was found in Keycloak. The cross-session verification proof is ...
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
6.4 Medium
CVSS3