Play Framework Session Encoding Spoofing Security Vulnerability
BID:61787
Info
Play Framework Session Encoding Spoofing Security Vulnerability
| Bugtraq ID: | 61787 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2013 12:00AM |
| Updated: | Aug 15 2013 12:00AM |
| Credit: | National Australia Bank Security Assurance Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Play Framework Session Encoding Spoofing Security Vulnerability
Play Framework is prone to a vulnerability that may allow attackers to spoof sessions.
Remote attackers can exploit this issue to perform spoofing attacks and impersonate another legitimate user. This may aid in further attacks.
This issue affects Play Framework versions 1.0 through 1.0.3.3, 1.1 through 1.1.2, 1.2 through 1.2.5, 2.0 through 2.0.5, and 2.1.0 through 2.1.2.
Play Framework is prone to a vulnerability that may allow attackers to spoof sessions.
Remote attackers can exploit this issue to perform spoofing attacks and impersonate another legitimate user. This may aid in further attacks.
This issue affects Play Framework versions 1.0 through 1.0.3.3, 1.1 through 1.1.2, 1.2 through 1.2.5, 2.0 through 2.0.5, and 2.1.0 through 2.1.2.
Exploit / POC
Play Framework Session Encoding Spoofing Security Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Play Framework Session Encoding Spoofing Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Play Framework Session Encoding Spoofing Security Vulnerability
References:
References: