7.4 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
17 packages
- keycloak-config-cli
- terraform-providers.keycloak
- keycloakPlugins.keycloak-orgs
- keycloakPlugins.keycloak-discord
- python313Packages.python-keycloak
- python314Packages.python-keycloak
- keycloakPlugins.keycloak-magic-link
- terraform-providers.keycloak_keycloak
- keycloakPlugins.keycloak-home-idp-discovery
- keycloakPlugins.keycloak-restrict-client-auth
- keycloakPlugins.keycloak-2fa-app-authenticator
- keycloakPlugins.keycloak-2fa-sms-authenticator
- keycloakPlugins.keycloak-secrets-vault-provider
- keycloakPlugins.apple-identity-provider-keycloak
- keycloakPlugins.keycloak-2fa-email-authenticator
- keycloakPlugins.keycloak-enforce-mfa-authenticator
- keycloakPlugins.keycloak-remember-me-authenticator
- @LeSuisse accepted
- @LeSuisse published on GitHub
Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow.
References
Affected products
- <26.7.4
Matching in nixpkgs
Ignored packages (17)
pkgs.keycloak-config-cli
Import YAML/JSON-formatted configuration files into Keycloak
pkgs.terraform-providers.keycloak
None
pkgs.keycloakPlugins.keycloak-orgs
Multi-tenancy on a single Keycloak realm via first-class organization objects
-
nixos-unstable -
- nixos-unstable-small 0.180
pkgs.keycloakPlugins.keycloak-discord
Keycloak Identity Provider extension for Discord
-
nixos-unstable -
- nixos-unstable-small 1.3.1
pkgs.python313Packages.python-keycloak
Provides access to the Keycloak API
pkgs.python314Packages.python-keycloak
Provides access to the Keycloak API
pkgs.keycloakPlugins.keycloak-magic-link
Magic Link Authentication for Keycloak
-
nixos-unstable -
- nixos-unstable-small 0.75
pkgs.terraform-providers.keycloak_keycloak
None
pkgs.keycloakPlugins.keycloak-home-idp-discovery
Keycloak authenticator to redirect users to their home identity provider by email domain
-
nixos-unstable -
- nixos-unstable-small 26.2.2
pkgs.keycloakPlugins.keycloak-restrict-client-auth
Keycloak authenticator to restrict authorization on clients
-
nixos-unstable -
- nixos-unstable-small 26.1.1
pkgs.keycloakPlugins.keycloak-2fa-app-authenticator
Keycloak MFA provider connecting a native mobile app for login approval
-
nixos-unstable -
- nixos-unstable-small 2fa-app-authenticator-26.6.5
pkgs.keycloakPlugins.keycloak-2fa-sms-authenticator
Keycloak authentication provider for 2FA via SMS
-
nixos-unstable -
- nixos-unstable-small 2fa-sms-authenticator-26.6.5
pkgs.keycloakPlugins.keycloak-secrets-vault-provider
Keycloak Vault SPI provider for OpenBao and HashiCorp Vault
-
nixos-unstable -
- nixos-unstable-small 1.0.0
pkgs.keycloakPlugins.apple-identity-provider-keycloak
Keycloak identity provider extension for Sign in with Apple
-
nixos-unstable -
- nixos-unstable-small 1.17.0
pkgs.keycloakPlugins.keycloak-2fa-email-authenticator
Keycloak authentication provider for 2FA via email OTP
-
nixos-unstable -
- nixos-unstable-small 2fa-email-authenticator-26.6.5
pkgs.keycloakPlugins.keycloak-enforce-mfa-authenticator
Keycloak authenticator that enforces MFA
-
nixos-unstable -
- nixos-unstable-small 26.6.5
pkgs.keycloakPlugins.keycloak-remember-me-authenticator
Custom authenticator for remembering the user logging in, even if no "Remember me" flag is set
-
nixos-unstable -
- nixos-unstable-small 1.0.0
Package maintainers
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@ap-1 Anish Pallati <i@anish.land>
-
@ngerstle Nicholas Gerstle <ngerstle@gmail.com>
-
@kritdass Krit Dass <dasskrit@gmail.com>
-
@jefferyoo Jeffery Oo <oojefferywm@proton.me>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@leona-ya Leona Maroni <nix@leona.is>