CVE-2024-7341 is a session fixation vulnerability in Keycloak's SAML adapters, affecting Red Hat Keycloak, Red Hat Single Sign-On, and Red Hat Enterprise Linux. The flaw allows an attacker to hijack a pre-authentication session, as the session ID and JSESSIONID cookie are not refreshed upon login, even when configured to do so. With a CVSS score of 7.1 (HIGH), this vulnerability has a high potential impact on confidentiality, integrity, and availability, but requires low privileges and user interaction, with high attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.2CPE matchmatch criteria | cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* | ||
>= 7.6, < 7.6.10CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:*:*:*:*:*:*:*:* | ||
>= 22.0, < 22.0.12CPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* | ||
>= 24.0, < 24.0.7CPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.