8.8

CVE-2017-1000150

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mahara ≫ Mahara Version 15.04 Update rc1
Mahara ≫ Mahara Version 15.04 Update rc2
Mahara ≫ Mahara Version 15.04.0
Mahara ≫ Mahara Version 15.04.1
Mahara ≫ Mahara Version 15.04.2
Mahara ≫ Mahara Version 15.04.3
Mahara ≫ Mahara Version 15.04.4
Mahara ≫ Mahara Version 15.04.5
Mahara ≫ Mahara Version 15.04.6
Mahara ≫ Mahara Version 15.10.0
Mahara ≫ Mahara Version 15.10.1
Mahara ≫ Mahara Version 15.10.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

https://bugs.launchpad.net/mahara/+bug/1567784
Patch
Third Party Advisory
Issue Tracking