← Back

CVE-2024-7341

nvd nist
Published: Sep 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

Affected (5)

3 products
Keycloak
Single Sign On
Build Of Keycloak
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 25.0.2
Configuration B
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
From 7.6 to 7.6.10
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0
Redhat
Enterprise Linux
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 22.0 to 22.0.12
From 24.0 to 24.0.7
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (12)

Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.