Impact
A flaw in Keycloak’s session management lets a user bypass a mandatory two‑factor authentication requirement that is enforced through a client policy. By manually visiting a specific session‑restart web link during the login sequence, the system clears the internal markers that track pending authentication steps, allowing the user to authenticate with only a password. The weakness identified is an Authentication Process flaw (CWE‑862) and the impact is the loss of the confidentiality guarantee that 2FA protects.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific patch versions are listed, so any installation of these products that implements client policies requiring two‑factor authentication is potentially vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates low technical severity, but the business impact of allowing users to circumvent additional authentication steps can be substantial, especially in compliance‑driven environments. EPSS data are unavailable and the issue is not listed in the CISA KEV catalog. The attack requires only manual access to a known web link during login, which means a credentialed or non‑credentialed user can exploit it if the session‑restart endpoint is reachable. Based on the description, the likely attack vector is a simple, client‑side action that can be performed by anyone who can trigger the login flow.
OpenCVE Enrichment