PT-2020-7599 · Cgilua · Cgilua
Felipe Daragon
·
Published
2020-02-06
·
Updated
2020-02-11
·
CVE-2014-10400
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CGILua versions 5.0.x
Description
The session.lua library uses sequential session IDs, making it easier for remote attackers to predict the session ID and hijack arbitrary sessions.
Recommendations
For CGILua versions 5.0.x, consider implementing a secure random session ID generation mechanism to prevent session hijacking. As a temporary workaround, consider regenerating session IDs at regular intervals to minimize the risk of exploitation.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cgilua