Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cq5-8cj7-g558

Опубликовано: 22 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

CodeIgniter4 Potential Session Handlers Vulnerability

Impact

When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to DatabaseHandler, MemcachedHandler, or RedisHandler, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages).

Patches

Upgrade to version 4.2.11 or later.

Workarounds

  • Use only one session cookie.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

codeigniter4/framework

composer
Затронутые версииВерсия исправления

< 4.2.11

4.2.11

EPSS

Процентиль: 54%
0.00311
Низкий

8.6 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.6
nvd
около 3 лет назад

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages). This issue has been patched, please upgrade to version 4.2.11 or later. As a workaround, use only one session cookie.

CVSS3: 8.6
debian
около 3 лет назад

CodeIgniter is a PHP full-stack web framework. When an application use ...

EPSS

Процентиль: 54%
0.00311
Низкий

8.6 High

CVSS3

Дефекты

CWE-287