Insufficiently protected credentials in Keycloak - CVE-2019-3868
Published: October 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to hijack user's session.
The vulnerability exists due to software may use the end user token (access or id token JWT) as a session cookie for browser sessions for OIDC. A remote attacker that has access to the service provider backend can hijack the user's browser session and gain unauthorized access to the application.
Affected software
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)
How to mitigate CVE-2019-3868
rh-sso7-keycloak (Red Hat package) - addressed in versions 3.4.17-1.Final_redhat_00001.1.jbcs.el6, 3.4.17-1.Final_redhat_00001.1.jbcs.el7
Red Hat Single Sign-On - addressed in versions 7.2.7, 7.3.1
External References
Related Security Bulletins
- Red Hat update for Red Hat OpenShift Application Runtimes Thorntail 2.5.0
- Insufficiently protected credentials in Red Hat Single Sign-On 7.2
- Insufficiently protected credentials in Red Hat Single Sign-On 7.2
- Insufficiently protected credentials in Red Hat Single Sign-On 7.2
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3