Red Hat Keycloak 25.0.1

CPE Details

Red Hat Keycloak 25.0.1
25.0.1
2024-10-02
18h10 +00:00
2024-10-02
18h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:keycloak:25.0.1:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

keycloak

Version

25.0.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-7341 2024-09-09
18h51 +00:00
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
7.1
High