CVE-2024-23679
Published Jan 19, 2024
Last updated 10 months ago
Overview
- Description
- Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:enonic:xp:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FC6521F-C0B8-4FE8-BE06-FAB57CFFE61A", "versionEndExcluding": "7.7.4" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0231ECC2-744B-4441-942B-514C943F7294" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD92F3AC-0C60-4588-B5DE-3488F7B38C18" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B807EF9-DADE-4C67-8AAF-E29C70D8D32F" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BB4FF1C-13D7-4385-A4EB-27750E88AE3B" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "890C984E-B1AD-4213-B355-DB26E6B1BE8D" }, { "criteria": "cpe:2.3:a:enonic:xp:7.8.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E156CC35-DC76-463E-8882-86C36814976E" } ], "operator": "OR" } ] } ]