Medium severity6.8NVD Advisory· Published Sep 20, 2023· Updated Jun 17, 2026
CVE-2022-3916
CVE-2022-3916
Description
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-parentMaven | < 20.0.2 | 20.0.2 |
Affected products
18cpe:/a:redhat:red_hat_single_sign_on:7.6+ 6 more
- cpe:/a:redhat:red_hat_single_sign_on:7.6
- cpe:/a:redhat:red_hat_single_sign_on:7.6.1
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el7range: 0:18.0.6-1.redhat_00001.1.el7sso
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el8range: 0:18.0.6-1.redhat_00001.1.el8sso
- cpe:/a:redhat:red_hat_single_sign_on:7.6::el9range: 0:18.0.6-1.redhat_00001.1.el9sso
- cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*
- Red Hat/RHEL-8 based Middleware Containersv5cpe:/a:redhat:rhosemc:1.0::el8Range: 7.6-20
cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
15- access.redhat.com/errata/RHSA-2022:8961nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2022:8962nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2022:8963nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2022:8964nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2022:8965nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:1043nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:1044nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:1045nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:1047nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:1049nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2022-3916nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-97g8-xfvw-q4hgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-3916ghsaADVISORY
- github.com/keycloak/keycloak/security/advisories/GHSA-97g8-xfvw-q4hgghsaWEB
News mentions
0No linked articles in our index yet.