PT-2024-39148 · Valeapp · Valeapp

Havelsan Inc

·

Published

2024-09-27

·

Updated

2024-10-04

·

CVE-2024-8643

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ValeApp versions prior to 2.0.0
Description: The issue is a Session Fixation vulnerability that allows for Brute Force and Session Hijacking. This vulnerability affects the authentication mechanism of the software, potentially allowing unauthorized access to user sessions.
Recommendations: For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to protect against brute force attacks and session hijacking, such as restricting access to sensitive areas of the application or implementing rate limiting on login attempts.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2024-8643

Affected Products

Valeapp