#VU31158 Session Fixation in Crowd Server - CVE-2018-20238

 

#VU31158 Session Fixation in Crowd Server - CVE-2018-20238

Published: February 13, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31158
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-20238
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Crowd Server
Software vendor:
Atlassian

Description

The vulnerability allows a remote authenticated user to read and manipulate data.

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.


Remediation

Install update from vendor's website.

External links