PT-2020-9052 · Red Hat · Infinispan

The-Cartographer

·

Published

2020-01-02

·

Updated

2023-12-27

·

CVE-2019-10158

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infinispan versions prior to 9.4.14.Final
Description A flaw was found in the improper implementation of the session fixation protection in the Spring Session integration, which can result in incorrect session handling.
Recommendations For versions prior to 9.4.14.Final, update to version 9.4.14.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the Spring Session integration until a patch is available.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2019-10158
GHSA-6X3V-RW2Q-9GX7

Affected Products

Infinispan