Skip to content

Session Fixation in lib-auth

Critical
rymsha published GHSA-4m5p-5w5w-3jcf Oct 12, 2022

Package

maven com.enonic.xp.lib.auth (Maven)

Affected versions

< 7.7.4

Patched versions

7.7.4, 7.8.0

Description

Impact

All id-providers using lib-auth login method.

Patches

0189975
2abac31
1f44674

Workarounds

Don't use lib-auth for login.
Java API uses low-level structures and allows to invalidate previous session before auth-info is added.

References

#9253

Severity

Critical

CVE ID

CVE-2024-23679

Weaknesses

No CWEs