REDHAT-BUG-2254375: Medium severity Red Hat Keycloak vulnerability
A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2254375?
The severity of REDHAT-BUG-2254375 is classified as a potential account takeover vulnerability.
How do I fix REDHAT-BUG-2254375?
To fix REDHAT-BUG-2254375, update to the latest patched version of Keycloak provided by Red Hat.
What product is affected by REDHAT-BUG-2254375?
The affected product for REDHAT-BUG-2254375 is Red Hat Build of Keycloak.
What causes the vulnerability in REDHAT-BUG-2254375?
The vulnerability in REDHAT-BUG-2254375 is caused by session hijacking due to re-authentication prompts.
Is there a workaround for REDHAT-BUG-2254375?
There are currently no recommended workarounds for REDHAT-BUG-2254375, and immediate patching is advised.