Lucene search

K
nvd[email protected]NVD:CVE-2020-10714
HistorySep 23, 2020 - 1:15 p.m.

CVE-2020-10714

2020-09-2313:15:15
CWE-384
web.nvd.nist.gov
6
wildfly elytron
authentication
session fixation

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.8%

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected configurations

Nvd
Node
redhatwildfly_elytronRange<1.11.3
Node
redhatcodeready_studioMatch12.0
OR
redhatdescision_managerMatch7.0
OR
redhatjboss_fuseMatch7.0.0
OR
redhatprocess_automationMatch7.0
Node
netapponcommand_insightMatch-
VendorProductVersionCPE
redhatwildfly_elytron*cpe:2.3:a:redhat:wildfly_elytron:*:*:*:*:*:*:*:*
redhatcodeready_studio12.0cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*
redhatdescision_manager7.0cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:*
redhatjboss_fuse7.0.0cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
redhatprocess_automation7.0cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
netapponcommand_insight-cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.8%