Impact
This vulnerability arises from a missing enforcement of the OneTimeUse condition in SAML assertions during IdP‑initiated broker flows within Keycloak. Because an attacker can capture a still‑unused assertion, the flaw allows replaying that assertion multiple times, effectively hijacking a legitimate user’s session and gaining unauthorized access.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific affected versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.4 signals moderate severity. No EPSS score is available, so the exploitation probability is unknown; the issue is not reported in CISA’s KEV catalog. Inferred from the description, the attack vector is likely remote via intercepted SAML assertions, requiring an attacker to obtain a valid yet unused assertion before replaying it. Successful exploitation would grant an attacker the privileges of the impersonated user.
OpenCVE Enrichment