Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
Published Sep 9, 2024
7.1
HIGHCVSS 3.1
EPSS 0.85%
Description
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
Affected products
No data.
Configuration 2
- ≥ 7.6 · < 7.6.10
Running on/with
- 7.0
- 8.0
- 9.0
Configuration 3
- ≥ 22.0 · < 22.0.12
- ≥ 24.0 · < 24.0.7
Configuration 4
- n/a
No data.
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-52
Fixed · RHSA-2024:6497
Red Hat Build of Keycloak
keycloak-services
Fixed · RHSA-2024:6501
Red Hat Build of Keycloak
keycloak-services
Fixed · RHSA-2024:6503
Red Hat Single Sign-On 7
keycloak-services
Fixed · RHSA-2024:6499
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el7sso
Fixed · RHSA-2024:6493
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el8sso
Fixed · RHSA-2024:6494
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el9sso
Fixed · RHSA-2024:6495
Red Hat build of Keycloak 22
rhbk/keycloak-operator-bundle:22.0.12-1
Fixed · RHSA-2024:6500
Red Hat build of Keycloak 22
rhbk/keycloak-rhel9-operator:22-20
Fixed · RHSA-2024:6500
Red Hat build of Keycloak 22
rhbk/keycloak-rhel9:22-17
Fixed · RHSA-2024:6500
Red Hat build of Keycloak 24
rhbk/keycloak-operator-bundle:24.0.7-4
Fixed · RHSA-2024:6502
Red Hat build of Keycloak 24
rhbk/keycloak-rhel9-operator:24-16
Fixed · RHSA-2024:6502
Red Hat build of Keycloak 24
rhbk/keycloak-rhel9:24-16
Fixed · RHSA-2024:6502
Red Hat JBoss Enterprise Application Platform 8
keycloak-services
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-52 | Fixed | RHSA-2024:6497 |
| Red Hat Build of Keycloak | keycloak-services | Fixed | RHSA-2024:6501 |
| Red Hat Build of Keycloak | keycloak-services | Fixed | RHSA-2024:6503 |
| Red Hat Single Sign-On 7 | keycloak-services | Fixed | RHSA-2024:6499 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el7sso | Fixed | RHSA-2024:6493 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el8sso | Fixed | RHSA-2024:6494 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.16-1.redhat_00001.1.el9sso | Fixed | RHSA-2024:6495 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-operator-bundle:22.0.12-1 | Fixed | RHSA-2024:6500 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-rhel9-operator:22-20 | Fixed | RHSA-2024:6500 |
| Red Hat build of Keycloak 22 | rhbk/keycloak-rhel9:22-17 | Fixed | RHSA-2024:6500 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-operator-bundle:24.0.7-4 | Fixed | RHSA-2024:6502 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9-operator:24-16 | Fixed | RHSA-2024:6502 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9:24-16 | Fixed | RHSA-2024:6502 |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This vulnerability is categorized as moderate severity rather than critical due to its specific exploitation conditions and impact. While it presents a session fixation risk, the attacker must first hijack a session before authentication. This pre-condition limits the exploitation vector to scenarios where an attacker has already gained some level of access or control. Additionally, the attack only impacts sessions where the `turnOffChangeSessionIdOnLogin` option is not set to true. Consequently, while it does pose a risk by potentially allowing unauthorized access if the session ID is not updated, the overall likelihood and impact of successful exploitation are mitigated by these constraints.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (20)
- https://access.redhat.com/errata/RHSA-2024:6493 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6494 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6495 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6497 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6499 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6500 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6501 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6502 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/errata/RHSA-2024:6503 vendor-advisoryx_refsource_REDHATMailing List
- https://access.redhat.com/security/cve/CVE-2024-7341 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302064 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2954 Advisory
- https://github.com/advisories/GHSA-5rxp-2rhr-qwqv Advisory
- https://github.com/advisories/GHSA-j76j-rqwj-jmvv
- https://github.com/keycloak/keycloak/commit/2341d6ee7a3567c58fd6a04a419fe4403e13374c
- https://github.com/keycloak/keycloak/commit/5b3de0c7e7f367103affe2f5167913a2ce021cf1
- https://github.com/keycloak/keycloak/commit/5e06da2f6794c695051605e26a01affa3a18f66b
- https://github.com/keycloak/keycloak/security/advisories/GHSA-5rxp-2rhr-qwqv
- https://nvd.nist.gov/vuln/detail/CVE-2024-7341
- https://www.cve.org/CVERecord?id=CVE-2024-7341
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub