CVE-2023-6787: Keycloak: session hijacking via re-authentication

Published Dec 13, 2023
·
Updated

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

Other sources

A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.

Red Hat

A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.

GitHub

Affected Software

5 affected componentsFixes available
maven/org.keycloak:keycloak-services>=23.0.0<24.0.3
24.0.3
maven/org.keycloak:keycloak-services<22.0.10
22.0.10
redhat Build Of Keycloak
redhat keycloak<22.0.10
redhat keycloak>=23.0.0<24.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.keycloak:keycloak-services to a version that resolves this vulnerability.

    Fixed in 24.0.3
  2. Upgrade

    Upgrade maven/org.keycloak:keycloak-services to a version that resolves this vulnerability.

    Fixed in 22.0.10

Event History

Dec 13, 2023
Data Sourced
via Red Hat·04:14 PM
DescriptionSeverityAffected Software
Apr 17, 2024
Advisory Published
via GitHub·06:25 PM
Apr 25, 2024
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-6787?

CVE-2023-6787 has a high severity rating due to its potential to allow session hijacking in Keycloak.

2

What software versions are affected by CVE-2023-6787?

CVE-2023-6787 affects Keycloak versions between 23.0.0 and 24.0.3, as well as versions up to 22.0.10.

3

How do I fix CVE-2023-6787?

To fix CVE-2023-6787, upgrade Keycloak to version 24.0.3 or 22.0.10 or later.

4

What type of vulnerability is CVE-2023-6787?

CVE-2023-6787 is a vulnerability related to the re-authentication mechanism in Keycloak.

5

How does CVE-2023-6787 affect user sessions?

CVE-2023-6787 allows unauthorized users to hijack active Keycloak sessions by triggering a new authentication process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203