
Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects the attack.
Static frontend that runs the OIDC flow (authorization code) against a Keycloak
and exposes the session_id hijacking hook of the PoC. It is served with nginx on
port 5174 for team use.
cd vps/pocCVE0264
docker compose up -d --build
It runs at http://maquina:5174. Open the provider firewall for
5174/TCP (just as you did with 8443).
The Keycloak URL is injected via environment (not hardcoded in the HTML): edit
KEYCLOAK_URL/REALM/CLIENT_ID in docker-compose.yml and restart — without rebuilding.
In the realm poc, client client1 (Admin Console → Clients → client1):
http://maquina:5174/*
(otherwise, Keycloak rejects the redirect back with "Invalid parameter: redirect_uri").http://maquina:5174
(otherwise, the fetch to the /token endpoint fails due to CORS and the login is left half-done).Keycloak uses a self-signed cert on 8443. Each team member, the first time,
must open https://maquina:8443 in their browser and accept the
certificate once. Otherwise, the frontend calls to Keycloak fail silently.
http://maquina:5174 → it redirects to the Keycloak login.code, a prompt shows the current session_id and
allows replacing it with that of another session (the core of the CVE-2023-0264 PoC).agente/) detects and alerts on this pattern.KEYCLOAK_URL in the compose + up -d.