Impact
An error in the OIDC Dynamic Client Registration component of Keycloak causes the backchannel logout offline token revocation setting to be omitted from serialization responses, and a client performing a standard update silently disables this setting. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout, allowing continued access to protected resources. The flaw is a missing authorization control (CWE-862) that permits an attacker to keep previously issued tokens alive beyond their intended lifecycle.
Affected Systems
The vulnerability affects Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7. No specific version ranges are listed, so any deployment of these products that uses OIDC dynamic client registration could be impacted.
Risk and Exploitability
With a CVSS score of 4.3, the technical severity is moderate; however the EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating current awareness is limited. The likely attack vector is via the DCR endpoint, which client applications normally use to register or update themselves. An attacker who can trigger or observe a client update can silence the revocation setting without needing elevated privileges, potentially allowing them to keep an offline token alive for replay or persistence attacks. Because no official fix or workaround is currently available, the risk remains present until a remediation is released or the configuration is hard‑wired to prevent automatic disabling of the revocation flag.
OpenCVE Enrichment