Session hijacking in Adobe Commerce (formerly Magento Commerce) - #VU8483

 

Session hijacking in Adobe Commerce (formerly Magento Commerce) - #VU8483

Published: September 15, 2017


Vulnerability identifier: #VU8483
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform session fixation attacks.

The vulnerability exists due to Customer and Admin tokens do not expire correctly. A remote attacker can login to the website through one of the expired user's sessions.

Affected software

Adobe Commerce (formerly Magento Commerce)

Remediation

Update to version 2.0.16 or 2.1.9.


External References

Related Security Bulletins