CVE-2023-6787: Red Hat Build Of Keycloak
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified
- Red Hat Keycloak: before 22.0.10 (fixed in 22.0.10); from 23.0.0, before 24.0.3 (fixed in 24.0.3)
Published 2024-04-25. Last modified 2026-06-17.