Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-376m-3rm2-9jm6

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Session Fixation in ipsilon

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

Пакеты

Наименование

ipsilon

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.2

2.0.2

Наименование

ipsilon

pip
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.1

1.2.1

Наименование

ipsilon

pip
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.2

1.1.2

Наименование

ipsilon

pip
Затронутые версииВерсия исправления

>= 1.0.0, < 1.0.3

1.0.3

EPSS

Процентиль: 91%
0.07142
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 8.2
redhat
почти 9 лет назад

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

CVSS3: 9.1
nvd
около 8 лет назад

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

CVSS3: 9.1
debian
около 8 лет назад

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 bef ...

oracle-oval
почти 9 лет назад

ELSA-2016-2809: ipsilon security update (IMPORTANT)

EPSS

Процентиль: 91%
0.07142
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-384