PT-2020-9052 · Red Hat · Infinispan

·

CVE-2019-10158

·

Published

2020-01-02

·

Updated

2023-12-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infinispan versions prior to 9.4.14.Final
Description A flaw was found in the improper implementation of the session fixation protection in the Spring Session integration, which can result in incorrect session handling.
Recommendations For versions prior to 9.4.14.Final, update to version 9.4.14.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the Spring Session integration until a patch is available.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10158
GHSA-6X3V-RW2Q-9GX7

Affected Products

Infinispan