High severity7.1OSV Advisory· Published Sep 9, 2024· Updated Aug 4, 2026
CVE-2024-7341
CVE-2024-7341
Description
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 22.0.12 | 22.0.12 |
org.keycloak:keycloak-servicesMaven | >= 23.0.0, < 24.0.7 | 24.0.7 |
org.keycloak:keycloak-servicesMaven | >= 25.0.0, < 25.0.5 | 25.0.5 |
Affected products
12- osv-coords7 versionspkg:apk/chainguard/keycloak-fips-policy-140-2pkg:maven/org.keycloak/keycloak-servicespkg:apk/chainguard/keycloak-bitnami-fipspkg:apk/chainguard/keycloak-iamguarded-fipspkg:apk/chainguard/keycloak-fipspkg:apk/chainguard/keycloak-fips-bitnami-compatpkg:apk/chainguard/keycloak-fips-policy-140-3
< 25.0.4-r0+ 6 more
- (no CPE)range: < 25.0.4-r0
- (no CPE)range: < 22.0.12
- (no CPE)range: < 25.0.4-r0
- (no CPE)range: < 25.0.4-r0
- (no CPE)range: < 25.0.4-r0
- (no CPE)range: < 25.0.4-r0
- (no CPE)range: < 25.0.4-r0
1.0-alpha-1, 1.0-alpha-1-12062013, 1.0-alpha-2, …+ 1 more
- (no CPE)range: 1.0-alpha-1, 1.0-alpha-1-12062013, 1.0-alpha-2, …
- cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*range: >=22.0,<22.0.12
cpe:2.3:a:redhat:single_sign-on:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:single_sign-on:*:*:*:*:*:*:*:*range: >=7.6,<7.6.10
- cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
Patches
Vulnerability mechanics
References
18- access.redhat.com/security/cve/CVE-2024-7341nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-5rxp-2rhr-qwqvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-7341ghsaADVISORY
- access.redhat.com/errata/RHSA-2024:6493nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6494nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6495nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6497nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6499nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6500nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6501nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6502nvdMailing ListWEB
- access.redhat.com/errata/RHSA-2024:6503nvdMailing ListWEB
- github.com/keycloak/keycloak/commit/2341d6ee7a3567c58fd6a04a419fe4403e13374cghsaWEB
- github.com/keycloak/keycloak/commit/5b3de0c7e7f367103affe2f5167913a2ce021cf1ghsaWEB
- github.com/keycloak/keycloak/commit/5e06da2f6794c695051605e26a01affa3a18f66bghsaWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-5rxp-2rhr-qwqvghsaWEB
- github.com/advisories/GHSA-j76j-rqwj-jmvvnvd
News mentions
0No linked articles in our index yet.