Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
It was discovered that the org.keycloak.services.resources.SocialResource.callback(String) method implementation lacked CSRF protection. A remote attacker could use this flaw to gain access to a KeyCloak managed accounts or perform other attacks.
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.
A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account.