Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17658
HistoryMay 02, 2019 - 5:51 a.m.

Session Hijacking

2019-05-0205:51:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.004 Low

EPSS

Percentile

72.2%

curl and libcurl are vulnerable to session hijacking. TLS/SSL backend incorrectly reuses client certificates for subsequent TLS connections in certain cases. An attacker could potentially use this flaw to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

References