BIT-keycloak-2024-7341

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2024-7341.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2024-7341
Aliases
Published
2026-08-25T11:41:25.578Z
Modified
2026-08-26T11:15:04.965736064Z
Summary
Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
Details

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0
Fixed
22.0.12
Introduced
24.0.0
Fixed
24.0.7

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2024-7341.json"