Описание
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
Ссылки
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.4.14 (включая)
cpe:2.3:a:infinispan:infinispan:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00509
Низкий
5.4 Medium
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-384
CWE-384
Связанные уязвимости
CVSS3: 5.4
redhat
больше 6 лет назад
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.
CVSS3: 9.8
github
около 6 лет назад
Improper implementation of the session fixation protection in Infinispan
EPSS
Процентиль: 66%
0.00509
Низкий
5.4 Medium
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-384
CWE-384