CVE-2024-23679

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enonic:xp:*:*:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:enonic:xp:7.8.0:rc3:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-19 21:15

Updated : 2024-01-26 19:12


NVD link : CVE-2024-23679

Mitre link : CVE-2024-23679

CVE.ORG link : CVE-2024-23679


JSON object : View

Products Affected

enonic

  • xp
CWE
CWE-384

Session Fixation