Логотип exploitDog
bind:CVE-2025-12390
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12390

Количество 3

Количество 3

nvd логотип

CVE-2025-12390

3 месяца назад

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2025-12390

3 месяца назад

A flaw was found in Keycloak. In Keycloak where a user can accidentall ...

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-rg35-5v25-mqvp

3 месяца назад

Keycloak vulnerable to session takeovers due to reuse of session identifiers

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12390

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

CVSS3: 6
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-12390

A flaw was found in Keycloak. In Keycloak where a user can accidentall ...

CVSS3: 6
0%
Низкий
3 месяца назад
github логотип
GHSA-rg35-5v25-mqvp

Keycloak vulnerable to session takeovers due to reuse of session identifiers

CVSS3: 6
0%
Низкий
3 месяца назад

Уязвимостей на страницу