QID 996992
Date Published: 2024-01-31
QID 996992: Java (Maven) Security Update for com.enonic.xp:lib-auth (GHSA-4hrp-m3f2-643j)
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4hrp-m3f2-643j for updates and patch information.
Vendor References
- GHSA-4hrp-m3f2-643j -
github.com/advisories/GHSA-4hrp-m3f2-643j
CVEs related to QID 996992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4hrp-m3f2-643j | com.enonic.xp:lib-auth |
|