​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-p2m6-2qw4-9j4g

Published

Last updated

https://images.chainguard.dev/security/CGA-p2m6-2qw4-9j4g
Package

keycloak-fips

Latest Update
Fixed
Fixed Version

24.0.3-r0

Aliases
  • CVE-2023-6787
  • GHSA-c9h6-v78w-52wj

Severity

6.5

Medium

CVSS V3

Summary

Keycloak vulnerable to session hijacking via re-authentication

Description

A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images