原始 OSV JSON{
"id": "GHSA-j76j-rqwj-jmvv",
"aliases": [],
"details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-5rxp-2rhr-qwqv. This link is maintained to preserve external references.\n\n# Original Description\nA session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when `the turnOffChangeSessionIdOnLogin` option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.",
"summary": "Duplicate Advisory: Keycloak Session Fixation vulnerability",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "25.0.0"
},
{
"fixed": "25.0.5"
}
]
}
],
"package": {
"name": "org.keycloak:keycloak-services",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "22.0.12"
}
]
}
],
"package": {
"name": "org.keycloak:keycloak-services",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "23.0.0"
},
{
"fixed": "24.0.7"
}
]
}
],
"package": {
"name": "org.keycloak:keycloak-services",
"ecosystem": "Maven"
}
}
],
"modified": "2024-12-20T17:50:21Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"published": "2024-09-09T21:31:22Z",
"withdrawn": "2024-12-20T17:50:21Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7341",
"type": "ADVISORY"
},
{
"url": "https://github.com/keycloak/keycloak/commit/2341d6ee7a3567c58fd6a04a419fe4403e13374c",
"type": "WEB"
},
{
"url": "https://github.com/keycloak/keycloak/commit/5b3de0c7e7f367103affe2f5167913a2ce021cf1",
"type": "WEB"
},
{
"url": "https://github.com/keycloak/keycloak/commit/5e06da2f6794c695051605e26a01affa3a18f66b",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6493",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6494",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6495",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6497",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6499",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6500",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6501",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6502",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:6503",
"type": "WEB"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2024-7341",
"type": "WEB"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2302064",
"type": "WEB"
},
{
"url": "https://github.com/keycloak/keycloak",
"type": "PACKAGE"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-384"
],
"severity": "HIGH",
"github_reviewed": true,
"nvd_published_at": "2024-09-09T19:15:14Z",
"github_reviewed_at": "2024-09-09T22:33:50Z"
}
}