Session Fixation in Crowd Server - CVE-2018-20238

 

Session Fixation in Crowd Server - CVE-2018-20238

Published: February 13, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31158
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20238
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.


Affected software

Crowd Server

How to mitigate CVE-2018-20238

Install update from vendor's website.

Crowd Server - update to 3.3.4

External References

Related Security Bulletins