A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the administrator's recent security configuration change. This is a logic flaw in session management increases the potential window for successful session hijacking or unauthorized long-term access persistence. The flaw lies in the session expiration logic relying on the session-local "remember-me" flag without validating the current realm-level configuration.
History

Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the administrator's recent security configuration change. This is a logic flaw in session management increases the potential window for successful session hijacking or unauthorized long-term access persistence. The flaw lies in the session expiration logic relying on the session-local "remember-me" flag without validating the current realm-level configuration.
Title keycloak-server: Too long and not settings compliant session Keycloak-server: too long and not settings compliant session
First Time appeared Redhat
Redhat build Keycloak
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References

Wed, 08 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title keycloak-server: Too long and not settings compliant session
Weaknesses CWE-613
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-10-23T14:09:31.901Z

Updated: 2025-10-23T14:31:49.115Z

Reserved: 2025-10-07T12:45:40.121Z

Link: CVE-2025-11429

cve-icon Vulnrichment

Updated: 2025-10-23T14:31:26.887Z

cve-icon NVD

Status : Received

Published: 2025-10-23T14:15:35.430

Modified: 2025-10-23T14:15:35.430

Link: CVE-2025-11429

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-07T00:00:00Z

Links: CVE-2025-11429 - Bugzilla