Red Hat Security Advisory: Red Hat build of Keycloak 24.0.7 Images Update
Description
Red Hat has released updated images for the Red Hat build of Keycloak 24.0.7 addressing three security issues: a session fixation vulnerability in Elytron SAML adapters (CVE-2024-7341), a One Time Passcode (OTP) validity period exceeding its expiration time (CVE-2024-7318), and an open redirect vulnerability on the account page (CVE-2024-7260). These vulnerabilities affect Red Hat build of Keycloak versions prior to 24.0.7. The update aligns with the standalone Keycloak 24.0.7 release and is intended for use within OpenShift Container Platform deployments. A patch is available and users are advised to back up their installations before applying the update.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory addresses three moderate severity vulnerabilities in Red Hat build of Keycloak prior to version 24.0.7. CVE-2024-7341 is a session fixation vulnerability in Elytron SAML adapters that could allow an attacker to fix a user's session identifier. CVE-2024-7318 involves the One Time Passcode (OTP) mechanism where OTPs remain valid longer than their intended expiration time, potentially allowing unauthorized use. CVE-2024-7260 is an open redirect vulnerability on the account page, which could be exploited to redirect users to malicious sites. Red Hat has released updated container images and packages for Keycloak 24.0.7 to remediate these issues. Users should back up their existing configurations and apply the update promptly.
Potential Impact
The vulnerabilities could allow attackers to hijack user sessions (session fixation), exploit OTPs beyond their expiration to bypass authentication controls, and redirect users to potentially malicious external sites via the open redirect flaw. These issues could undermine the security of authentication and user session management in environments using affected Keycloak versions, potentially leading to unauthorized access or phishing attacks. However, no known exploits in the wild have been reported at this time.
Mitigation Recommendations
A patch is available in Red Hat build of Keycloak version 24.0.7. Users should back up their existing installations, including applications, configuration files, and databases, before applying the update. Deploying the updated Keycloak 24.0.7 images or packages will remediate the session fixation, OTP validity, and open redirect vulnerabilities. No additional vendor-recommended mitigations are specified beyond applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:6502
- Cve Count
- 3
- Additional Cves
- ["CVE-2024-7318","CVE-2024-7341"]
Threat ID: 6a1df669e29bf47b50461a52
Added to database: 06/01/2026, 21:15:21 UTC
Last enriched: 09/17/2026, 23:17:18 UTC
Last updated: 10/10/2026, 06:48:11 UTC
Views: 147
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.