keycloak: session hijack using the user access token
Published Apr 24, 2019
3.8
MEDIUMCVSS 3.0
EPSS 1.00%
Description
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
Affected products
-
- Version affects up to 6.0.0 versionStatusaffectedConstraints-
- Version
No data.
Red Hat Runtimes Spring Boot 2.1.12
keycloak
Fixed · RHSA-2020:2366
Red Hat Single Sign-On 7.2 for RHEL 6
rh-sso7-keycloak-0:3.4.17-1.Final_redhat_00001.1.jbcs.el6
Fixed · RHSA-2019:0857
Red Hat Single Sign-On 7.2 for RHEL 7
rh-sso7-keycloak-0:3.4.17-1.Final_redhat_00001.1.jbcs.el7
Fixed · RHSA-2019:0856
Red Hat Single Sign-On 7.2.7 zip
n/a
Fixed · RHSA-2019:0868
Red Hat Single Sign-On 7.3.1 zip
n/a
Fixed · RHSA-2019:1140
Text-Only RHOAR
n/a
Fixed · RHSA-2019:2998
Red Hat Fuse 7
keycloak
Will not fix
Red Hat Mobile Application Platform 4
keycloak
Out of support scope
Red Hat OpenShift Application Runtimes
keycloak
Affected
Red Hat support for Spring Boot
keycloak
Affected
streams for Apache Kafka
keycloak
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Runtimes Spring Boot 2.1.12 | keycloak | Fixed | RHSA-2020:2366 |
| Red Hat Single Sign-On 7.2 for RHEL 6 | rh-sso7-keycloak-0:3.4.17-1.Final_redhat_00001.1.jbcs.el6 | Fixed | RHSA-2019:0857 |
| Red Hat Single Sign-On 7.2 for RHEL 7 | rh-sso7-keycloak-0:3.4.17-1.Final_redhat_00001.1.jbcs.el7 | Fixed | RHSA-2019:0856 |
| Red Hat Single Sign-On 7.2.7 zip | n/a | Fixed | RHSA-2019:0868 |
| Red Hat Single Sign-On 7.3.1 zip | n/a | Fixed | RHSA-2019:1140 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2019:2998 |
| Red Hat Fuse 7 | keycloak | Will not fix | n/a |
| Red Hat Mobile Application Platform 4 | keycloak | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | keycloak | Affected | n/a |
| Red Hat support for Spring Boot | keycloak | Affected | n/a |
| streams for Apache Kafka | keycloak | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:L/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 1.00% (0.01005) | 61.71th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.00% (0.01005) | 61.47th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.13% (0.00129) | 48.23th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.13% (0.00129) | 47.16th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.11% (0.00112) | 43.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Feb 4, 2022 | 8.13% (0.08128) | 82.07th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.77% (0.04773) | 77.96th | v1 |
| Jan 6, 2022 | 4.77% (0.04773) | 77.75th | v1 |
| Jan 5, 2022 | 1.10% (0.01105) | 67.44th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.10% (0.01105) | 0.00th | v1 |
References (9)
- http://www.securityfocus.com/bid/108061 vdb-entryx_refsource_BIDThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1140 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2998 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-3868 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1679144 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3868 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-gc52-xj6p-9pxp Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3868
- https://www.cve.org/CVERecord?id=CVE-2019-3868
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108061 | vdb-entryx_refsource_BIDThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:1140 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:2998 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-3868 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1679144 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3868 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-gc52-xj6p-9pxp | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-3868 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-3868 |
Change history (0)
No recorded changes yet.