Описание
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the expires field is overriden if the maxAge field was set.
This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This vulnerability has been patched 10.8.0.
Ссылки
EPSS
Процентиль: 57%
0.00351
Низкий
7.4 High
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 7.4
github
больше 1 года назад
@fastify/session reuses destroyed session cookie
EPSS
Процентиль: 57%
0.00351
Низкий
7.4 High
CVSS3
Дефекты
CWE-613