Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8638

Опубликовано: 12 июл. 2017
Источник: debian

Описание

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ipsilonitppackage

Примечания

  • https://ipsilon-project.org/advisory/CVE-2016-8638.txt

  • https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461c

Связанные уязвимости

CVSS3: 8.2
redhat
почти 9 лет назад

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

CVSS3: 9.1
nvd
около 8 лет назад

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

CVSS3: 9.1
github
больше 3 лет назад

Session Fixation in ipsilon

oracle-oval
почти 9 лет назад

ELSA-2016-2809: ipsilon security update (IMPORTANT)