CVE ID: CVE-2025-11429 Severity: Moderate (CVSS v3 Score: 5.4) Description: A flaw was found in Keycloak where Keycloak does not immediately enforce the clearing of the "Remember Me" flag when making user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the administrator's recent security configuration change. Mitigation: No mitigation is currently available or the options do not meet the Red Hat Product Security criteria. Additional Information: - Bugzilla 742748: keycloak-server: Too long and not settings compliant session - CWE-613: Insufficient Session Expiration Affected Packages: RHQ/Keycloak-Server CVSS v3 Score Breakdown: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None CWE: CWE-613 (Access Control) Acknowledgements: Discovered by Alexander Schwartz (Red Hat)