Impact
A flaw in Keycloak's TokenManager causes revocation requests using a "not-before" policy to be silently ignored when the realm’s not-before value is older but non-zero, allowing previously issued tokens to remain valid for session refreshes and user data access after an administrator attempts to invalidate them. This missing authorization weakness permits re‑use of tokens beyond the intended revocation window.
Affected Systems
The vulnerability affects Red Hat products built on Keycloak, including Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7. All current releases of these products that expose the TokenManager component are potentially impacted until a fix is released.
Risk and Exploitability
With a CVSS score of 4.2 the issue is of moderate severity; the EPSS score is less than 1% (0.131%) and it is not listed in the KEV catalog. The likely attack vector is via an administrative interface or management API that invokes the not‑before revocation function, and an attacker who can submit that request could maintain or elevate access with previously issued tokens. Because the flaw depends on the realm configuration, exploitation requires that an admin perform a revocation while the realm’s older non‑zero policy is in effect, so the risk is limited but still noteworthy for environments that rely on revocation to restrict token reuse.
OpenCVE Enrichment