CVE detail
CVE-2022-3916 — CVE-2022-3916
Published 2023-09-20 · Modified 2026-06-17 · Vendor redhat · Product keycloak · Source nvd
MEDIUM
severity
CVSS-derived band
0.0095
EPSS probability
exploitation probability, 30d
58.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References