PT-2024-39148 · Valeapp · Valeapp
Havelsan Inc
·
Published
2024-09-27
·
Updated
2024-10-04
·
CVE-2024-8643
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ValeApp versions prior to 2.0.0
Description:
The issue is a Session Fixation vulnerability that allows for Brute Force and Session Hijacking. This vulnerability affects the authentication mechanism of the software, potentially allowing unauthorized access to user sessions.
Recommendations:
For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to protect against brute force attacks and session hijacking, such as restricting access to sensitive areas of the application or implementing rate limiting on login attempts.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Valeapp