Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-12390

10 месяцев назад

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2025-12390

10 месяцев назад

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2025-12390

10 месяцев назад

A flaw was found in Keycloak. In Keycloak where a user can accidentall ...

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-rg35-5v25-mqvp

10 месяцев назад

Keycloak vulnerable to session takeovers due to reuse of session identifiers

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-12390

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-12390

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-12390

A flaw was found in Keycloak. In Keycloak where a user can accidentall ...

CVSS3: 6
0%
Низкий
10 месяцев назад
github логотип
GHSA-rg35-5v25-mqvp

Keycloak vulnerable to session takeovers due to reuse of session identifiers

CVSS3: 6
0%
Низкий
10 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.