Vulnerability Name: | CVE-2017-1000150 (CCN-134461) | ||||||||||||
Assigned: | 2016-10-21 | ||||||||||||
Published: | 2016-10-21 | ||||||||||||
Updated: | 2017-11-13 | ||||||||||||
Summary: | Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-384 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1000150 Source: CCN Type: Mahara Bugs: 1567784 Session ID's not being regenerated Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://bugs.launchpad.net/mahara/+bug/1567784 Source: XF Type: UNKNOWN mahara-cve20171000150-session-hijacking(134461) Source: CCN Type: Mahara Web site Mahara | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |