A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when using Undertow was found despite Undertow switching the session ID after authentication.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1830206 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-18 10:15
Updated : 2022-04-26 10:40
NVD link : CVE-2021-20324
Mitre link : CVE-2021-20324
JSON object : View
CWE
CWE-384
Session Fixation
Products Affected
redhat
- wildfly_elytron
- jboss_enterprise_application_platform
- single_sign-on
- descision_manager
- process_automation
- codeready_studio