CVE-2024-23679
19.01.2024, 21:15
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.Enginsight
Vendor | Product | Version |
---|---|---|
enonic | xp | 𝑥 < 7.7.4 |
enonic | xp | 7.8.0:beta1 |
enonic | xp | 7.8.0:beta2 |
enonic | xp | 7.8.0:beta3 |
enonic | xp | 7.8.0:rc1 |
enonic | xp | 7.8.0:rc2 |
enonic | xp | 7.8.0:rc3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References