CVE-2019-10158

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10158
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10158.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10158
Aliases
Published
2020-01-02T15:15:11Z
Modified
2024-09-03T02:21:54.789844Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

References

Affected packages

Git / github.com/infinispan/infinispan

Affected ranges

Type
GIT
Repo
https://github.com/infinispan/infinispan
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected

Affected versions

5.*

5.1.0.FINAL

9.*

9.3.0.Beta1
9.3.0.CR1
9.4.10.Final
9.4.11.Final
9.4.13.Final
9.4.14.Final
9.4.7.Final
9.4.8.Final