A session fixation attack allows an attacker to hijack a legitimate user session. The attack investigates a flaw in how the online application handles the session ID, especially the susceptible web application.
<= v1.6.3
The vulnerability has been fixed in v1.6.4.
https://github.com/KubeOperator/KubePi/commit/1e9c550356c1a425a742480efcf743d373e98dcb : A session fixation attack allows an attacker to hijack a legitimate user session.
It is recommended to upgrade the version to v1.6.4.
If you have any questions or comments about this advisory, please open an issue.
{ "github_reviewed_at": "2023-01-09T21:57:10Z", "cwe_ids": [ "CWE-384" ], "nvd_published_at": "2023-01-10T21:15:00Z", "severity": "HIGH", "github_reviewed": true }