CVE-2025-12390

Source
https://cve.org/CVERecord?id=CVE-2025-12390
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12390.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12390
Aliases
Downstream
Related
Published
2025-10-28T14:15:57.980Z
Modified
2026-03-15T22:50:11.935324Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12390.json"