Lucene search

K
osvGoogleOSV:GHSA-7FHR-2694-RG79
HistoryFeb 15, 2022 - 1:39 a.m.

Session Fixation in WildFly Elytron

2022-02-1501:39:57
Google
osv.dev
12
session fixation
wildfly elytron
data confidentiality
data integrity
system availability

EPSS

0.002

Percentile

55.8%

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

0.002

Percentile

55.8%