[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2023-6787Date: (C)2024-04-25   (M)2024-04-26


A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

Reference:
RHBZ#2254375
RHSA-2024:1867
RHSA-2024:1868
https://access.redhat.com/security/cve/CVE-2023-6787

CWE    1
CWE-287
XCCDF    1

© SecPod Technologies