CVE-2019-10158

CRITICAL9.8EPSS 0.51%

Improper implementation of the session fixation protection in Infinispan

發布日:2020/1/21修改日:2024/2/20

描述

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)