Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g68x-c5mc-5vwr

Опубликовано: 31 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

EPSS

Процентиль: 15%
0.00048
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

EPSS

Процентиль: 15%
0.00048
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-384