Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pocKeycloakCVE-2023-0264 — Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects the attack. | Kitploit
Tools/GitHubGitHub/eliangonzi00/pockeycloakcve-2023-0264
Defensive ToolsVulnerability AnalysisExploitationImpersonation ToolsWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationIntrusion Detection

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Red Teaming
GitHubeliangonzi00/pockeycloakcve-2023-0264

pocKeycloakCVE-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects the attack.

View Repository
222 months agoNot yet reviewed
Share

PoC CVE-2023-0264 — frontend (OIDC session hijacking)

Static frontend that runs the OIDC flow (authorization code) against a Keycloak and exposes the session_id hijacking hook of the PoC. It is served with nginx on port 5174 for team use.

Launching it (on the VPS)

cd vps/pocCVE0264
docker compose up -d --build

It runs at http://maquina:5174. Open the provider firewall for 5174/TCP (just as you did with 8443).

The Keycloak URL is injected via environment (not hardcoded in the HTML): edit KEYCLOAK_URL/REALM/CLIENT_ID in docker-compose.yml and restart — without rebuilding.

⚠️ Keycloak requirements (WITHOUT this the login/token fails)

In the realm poc, client client1 (Admin Console → Clients → client1):

  1. Valid redirect URIs → add http://maquina:5174/* (otherwise, Keycloak rejects the redirect back with "Invalid parameter: redirect_uri").
  2. Web origins → add http://maquina:5174 (otherwise, the fetch to the /token endpoint fails due to CORS and the login is left half-done).

⚠️ Self-signed certificate

Keycloak uses a self-signed cert on 8443. Each team member, the first time, must open https://maquina:8443 in their browser and accept the certificate once. Otherwise, the frontend calls to Keycloak fail silently.

How the PoC is used

  1. You open http://maquina:5174 → it redirects to the Keycloak login.
  2. When coming back with the code, a prompt shows the current session_id and allows replacing it with that of another session (the core of the CVE-2023-0264 PoC).
  3. If the exchange is completed, the token remains bound to the injected session. The security agent (folder agente/) detects and alerts on this pattern.

Notes

  • Served over HTTP (5174); Keycloak over HTTPS (8443): the flow works (http→https request allowed). For frontend HTTPS, a cert/reverse-proxy would be needed.
  • It is a PoC tool for authorized testing against your own Keycloak. If you expose it publicly, consider restricting access (IP, basic auth on the proxy) so it doesn't leave a hijack client open to anyone.
  • Changing Keycloak instance = change KEYCLOAK_URL in the compose + up -d.
Download Tool