{ "id": "CVE-2024-23679", "sourceIdentifier": "disclosure@vulncheck.com", "published": "2024-01-19T21:15:10.073", "lastModified": "2024-01-19T22:52:48.170", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.\n\n" } ], "metrics": {}, "weaknesses": [ { "source": "disclosure@vulncheck.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-384" } ] } ], "references": [ { "url": "https://github.com/advisories/GHSA-4m5p-5w5w-3jcf", "source": "disclosure@vulncheck.com" }, { "url": "https://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff", "source": "disclosure@vulncheck.com" }, { "url": "https://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4", "source": "disclosure@vulncheck.com" }, { "url": "https://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842", "source": "disclosure@vulncheck.com" }, { "url": "https://github.com/enonic/xp/issues/9253", "source": "disclosure@vulncheck.com" }, { "url": "https://github.com/enonic/xp/security/advisories/GHSA-4m5p-5w5w-3jcf", "source": "disclosure@vulncheck.com" }, { "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-4m5p-5w5w-3jcf", "source": "disclosure@vulncheck.com" } ] }