Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fhr-2694-rg79

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Session Fixation in WildFly Elytron

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Пакеты

Наименование

org.wildfly.security:wildfly-elytron

maven
Затронутые версииВерсия исправления

<= 1.11.3

1.11.4

EPSS

Процентиль: 58%
0.00366
Низкий

7.5 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 7.5
redhat
почти 6 лет назад

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.5
nvd
больше 5 лет назад

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

Процентиль: 58%
0.00366
Низкий

7.5 High

CVSS3

Дефекты

CWE-384