Impact
A flaw in Keycloak’s first broker login flow creates a temporary proof to confirm cross‑browser account linking that is not cleared after link establishment or removal. The residual proof can be reused by an attacker who controls the external identity provider, allowing that attacker to silently re‑link a victim’s account without user confirmation and gain unauthorized access to the account.
Affected Systems
The affected products are Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7. Any deployment of these products that uses brokered identity providers may be vulnerable. Specific affected versions are not listed in the data provided.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a low exploitation likelihood, and the issue is not listed in the CISA KEV catalog. Attackers would need control over the external identity provider and a user who had previously confirmed an account link. If exploited, an attacker would gain unauthorized access to the victim’s account without further confirmation.
OpenCVE Enrichment