Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23679.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-384"
]
}{
"cpe": [
"cpe:2.3:a:enonic:xp:*:*:*:*:*:*:*:*",
"cpe:2.3:a:enonic:xp:7.8.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:enonic:xp:7.8.0:rc2:*:*:*:*:*:*",
"cpe:2.3:a:enonic:xp:7.8.0:rc3:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.7.4"
},
{
"introduced": "7.8.0-rc1"
},
{
"last_affected": "7.8.0-rc1"
},
{
"introduced": "7.8.0-rc2"
},
{
"last_affected": "7.8.0-rc2"
},
{
"introduced": "7.8.0-rc3"
},
{
"last_affected": "7.8.0-rc3"
}
]
}