CVE-2022-3916 is a medium-severity flaw in Keycloak's offline_access scope, affecting Red Hat products like Keycloak, Enterprise Linux, and OpenShift Container Platform. It allows an attacker to reuse session IDs across root and user authentication sessions, enabling them to obtain a token for a previously authenticated user by leveraging a refresh token. The vulnerability has a CVSS score of 6.8, indicating a network attack vector with high attack complexity and high confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.2CPE matchmatch criteria | cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:* | ||
4.9CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:* | ||
4.10CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.