Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38841
HistoryJan 12, 2023 - 2:59 a.m.

Session Fixation

2023-01-1202:59:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
session fixation
github
vulnerability
session expiration
access token
user locked

EPSS

0.001

Percentile

45.0%

github.com/zitadel/zitadel is vulnerable to session fixation. The vulnerability exists due to the insufficient session expiration mechanism used in the library, allowing an attacker to use the access token to continue the session without refreshing the token when the user is locked or deactivated.

EPSS

0.001

Percentile

45.0%

Related for VERACODE:38841