Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2fp-3rf2-fmrf

Опубликовано: 19 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when using Undertow was found despite Undertow switching the session ID after authentication.

A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when using Undertow was found despite Undertow switching the session ID after authentication.

5.4 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

nvd
почти 4 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

5.4 Medium

CVSS3

Дефекты

CWE-384