Session Fixation in WildFly Elytron
High severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
<= 1.11.3
Patched versions
1.11.4
Description
Published by the National Vulnerability Database
Sep 23, 2020
Published to the GitHub Advisory Database
Feb 15, 2022
Reviewed
Jun 24, 2022
Last updated
Jan 29, 2023
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References