Keycloak Session Management Logic Flaw CVE-2025-XXXXX (Moderate)

Listen to this Post

How the CVE Works

This vulnerability is a logic flaw in Keycloak’s session expiration mechanism. When an administrator disables the “Remember Me” feature at the realm level, this change is not propagated to existing, active user sessions. The session’s lifetime is determined at creation time based on the realm’s settings active in that moment. Each session stores a local `remember-me` flag. The session expiration logic only checks this local flag, not the current global realm configuration. Consequently, sessions created while “Remember Me” was enabled retain their extended lifespan (e.g., 30 days) even after “Remember Me” is globally disabled, which is intended to enforce a much shorter session duration (e.g., 1 hour). This creates a window where old sessions remain valid, bypassing the new security policy and increasing the risk of session hijacking.
Platform: Keycloak
Version: Affected versions
Vulnerability: Logic Flaw
Severity: Moderate

date: 2024-10-23

Prediction: Patch by 2024-11-13

What Undercode Say:

`grep -r “rememberMe” /path/to/keycloak/services/src/main/java/org/keycloak/sessions/`

`keycloak/bin/kc.sh start –debug`

`curl -H “Authorization: Bearer $OLD_TOKEN” $KEYCLOAK_API/userinfo`

How Exploit:

An attacker who has previously stolen a valid, long-lived session cookie (e.g., via XSS) can continue to use it for unauthorized access long after “Remember Me” has been disabled by an administrator. The exploit requires no interaction and relies on the inherent session validity.

Protection from this CVE

Upgrade Keycloak upon patch release. As a temporary mitigation, administrators can forcibly log out all active users immediately after disabling the “Remember Me” feature, terminating all existing sessions.

Impact:

Unauthorized access persistence, Session hijacking, Security policy bypass.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top