A flaw was found in Keycloak Core package. After performing authentication it is noticed that AUTH_SESSION_ID cookie is not changing and after logout the cookie is not cleared. Authenticating a user but failing to provision a new session identifier gives an attacker the opportunity to steal authenticated sessions of victim users. This may enable a malicious user to break the data confidentiality and integrity of victim users.