Impact
A flaw was discovered in the broker login flow of Keycloak where a temporary proof created to confirm cross‑browser account linking is not cleared after the link is established or removed. The leftover proof can be reused by an attacker who controls the external identity provider, allowing them to silently re‑establish a link and gain unauthorized access to the victim’s account without user confirmation. The vulnerability is a trust‑verification weakness (CWE-613) that can lead to unauthorized access to an authenticated user’s account and potentially to further privilege escalation within the application.
Affected Systems
The affected vendors are Red Hat with its Build of Keycloak and the Red Hat Single Sign‑On 7 product. Any deployment of these products that uses brokered identity providers may be vulnerable. The specific affected versions are not listed in the input, but the vulnerability appears in the first broker login flow of the mentioned products.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation likelihood is low but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers would need control over the external identity provider and a user who had previously confirmed an account link to exploit the residual proof. Because the proof is reused without re‑authentication, a successful exploit results in unauthorized account access and potentially broader compromise if the user holds privileged roles.
OpenCVE Enrichment