Intel

AIKIDO-2024-10366

keycloak-saml-wildfly-elytron-adapter is vulnerable to Session Fixation

Session FixationCVE-2024-7341 Published Oct 25, 2024

75

High Risk

This Affects:

javakeycloak-saml-wildfly-elytron-adapter
0.0.1 - 22.0.11
Fixed in 22.0.12
24.0.0 - 24.0.6
Fixed in 24.0.7
25.0.0 - 25.0.4
Fixed in 25.0.5
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to session fixation due to improper handling of session IDs and JSESSIONID cookies during the login process. An attacker can exploit this vulnerability by providing a pre-set session ID, which the application then uses, allowing the attacker to hijack the session after the user logs in.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

keycloak-saml-wildfly-elytron-adapter is vulnerable to Session Fixation in versions 0.0.1 - 22.0.11, 24.0.0 - 24.0.6 and 25.0.0 - 25.0.4.

How to fix this

Upgrade the org.keycloak:keycloak-saml-wildfly-elytron-adapter library to a patch version.