The SAML adapter is expected to change the sesion ID (and the respective JSESSIONID cookie) when the login is performed (except if the option turnOffChangeSessionIdOnLogin is true). This way the session ID is modified in the login to change the previous non-authenticated ID to a new one and avoid using the same valiue (just to protect against a possible cookie hijacking). Requirements to exploit: You need to hijack the current session before authentication and it will be valid after it. Session fixation issue. Component affected: org.keycloak.services Version affected: <= 25.0.2 (also present in RHBK and RHSSO elytron variant).
This issue has been addressed in the following products: Red Hat Single Sign-On Via RHSA-2024:6499 https://access.redhat.com/errata/RHSA-2024:6499
This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 7 Via RHSA-2024:6493 https://access.redhat.com/errata/RHSA-2024:6493
This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 8 Via RHSA-2024:6494 https://access.redhat.com/errata/RHSA-2024:6494
This issue has been addressed in the following products: Red Hat build of Keycloak 22 Via RHSA-2024:6501 https://access.redhat.com/errata/RHSA-2024:6501
This issue has been addressed in the following products: Red Hat build of Keycloak 24 Via RHSA-2024:6502 https://access.redhat.com/errata/RHSA-2024:6502
This issue has been addressed in the following products: Red Hat build of Keycloak 22 Via RHSA-2024:6503 https://access.redhat.com/errata/RHSA-2024:6503
This issue has been addressed in the following products: Red Hat build of Keycloak 22 Via RHSA-2024:6500 https://access.redhat.com/errata/RHSA-2024:6500
This issue has been addressed in the following products: Red Hat Single Sign-On 7.6 for RHEL 9 Via RHSA-2024:6495 https://access.redhat.com/errata/RHSA-2024:6495
This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2024:6497 https://access.redhat.com/errata/RHSA-2024:6497
(In reply to errata-xmlrpc from comment #9) > This issue has been addressed in the following products: > > RHEL-8 based Middleware Containers > > Via RHSA-2024:6497 https://access.redhat.com/errata/RHSA-2024:6497 https://101games.io Yess