CVE-2022-3916
published 2023-09-20CVE-2022-3916: A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due…
PriorityP341medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
0.95%
57.5th percentile
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 20.0.2 | 20.0.2 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
ghsa·2022-12-13
CVE-2022-3916 [MEDIUM] CWE-287 Keycloak vulnerable to session takeover with OIDC offline refreshtokens
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
An issue was discovered in Keycloak when using a client with the `offline_access` scope. Reuse of session ids across root and user authentication sessions and a lack of root session validation enabled attackers to resolve a user session attached to a different previously authenticated user.
This issue most affects users of shared computers. Suppose a user logs out of their account (without clearing their cookies) in a mobile app or similar client that includes the `offline_access` scope, and another user authenticates to the application. In that case, it will share the same root session id, and when utilizing the refresh token, they will be issued a token for the original user.
OSV
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
osv·2022-12-13
CVE-2022-3916 [MEDIUM] Keycloak vulnerable to session takeover with OIDC offline refreshtokens
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
An issue was discovered in Keycloak when using a client with the `offline_access` scope. Reuse of session ids across root and user authentication sessions and a lack of root session validation enabled attackers to resolve a user session attached to a different previously authenticated user.
This issue most affects users of shared computers. Suppose a user logs out of their account (without clearing their cookies) in a mobile app or similar client that includes the `offline_access` scope, and another user authenticates to the application. In that case, it will share the same root session id, and when utilizing the refresh token, they will be issued a token for the original user.
Red Hat
keycloak: Session takeover with OIDC offline refreshtokens
vendor_redhat·2022-11-09·CVSS 6.8
CVE-2022-3916 [MEDIUM] CWE-384 keycloak: Session takeover with OIDC offline refreshtokens
keycloak: Session takeover with OIDC offline refreshtokens
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2022:8961https://access.redhat.com/errata/RHSA-2022:8962https://access.redhat.com/errata/RHSA-2022:8963https://access.redhat.com/errata/RHSA-2022:8964https://access.redhat.com/errata/RHSA-2022:8965https://access.redhat.com/errata/RHSA-2023:1043https://access.redhat.com/errata/RHSA-2023:1044https://access.redhat.com/errata/RHSA-2023:1045https://access.redhat.com/errata/RHSA-2023:1047https://access.redhat.com/errata/RHSA-2023:1049https://access.redhat.com/security/cve/CVE-2022-3916https://bugzilla.redhat.com/show_bug.cgi?id=2141404https://access.redhat.com/errata/RHSA-2022:8961https://access.redhat.com/errata/RHSA-2022:8962https://access.redhat.com/errata/RHSA-2022:8963https://access.redhat.com/errata/RHSA-2022:8964https://access.redhat.com/errata/RHSA-2022:8965https://access.redhat.com/errata/RHSA-2023:1043https://access.redhat.com/errata/RHSA-2023:1044https://access.redhat.com/errata/RHSA-2023:1045https://access.redhat.com/errata/RHSA-2023:1047https://access.redhat.com/errata/RHSA-2023:1049https://access.redhat.com/security/cve/CVE-2022-3916https://bugzilla.redhat.com/show_bug.cgi?id=2141404
2023-09-20
Published