Session fixation in Adobe Commerce (formerly Magento Commerce) - #VU8469

 

Session fixation in Adobe Commerce (formerly Magento Commerce) - #VU8469

Published: September 15, 2017


Vulnerability identifier: #VU8469
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform session fixation attacks.

The vulnerability exists due an error in session expiraton functinality. A remote attacker can login to the website through one of the expired user's sessions.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins