Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10158

Опубликовано: 23 мая 2019
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7infinispanNot affected
Red Hat Fuse 7camelNot affected
Red Hat JBoss Data Virtualization 6infinispanNot affected
Red Hat JBoss Enterprise Application Platform 6infinispanNot affected
Red Hat JBoss Enterprise Application Platform 7infinispanNot affected
Red Hat JBoss Fuse 6camelNot affected
Red Hat JBoss Fuse Service Works 6infinispanNot affected
Red Hat JBoss Operations Network 3infinispanNot affected
Red Hat OpenShift Application RuntimesinfinispanNot affected
Red Hat OpenStack Platform 13 (Queens)opendaylightNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-384
https://bugzilla.redhat.com/show_bug.cgi?id=1714359infinispan: Session fixation protection broken for Spring Session integration

EPSS

Процентиль: 66%
0.00509
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

CVSS3: 9.8
github
около 6 лет назад

Improper implementation of the session fixation protection in Infinispan

EPSS

Процентиль: 66%
0.00509
Низкий

5.4 Medium

CVSS3