CVE-2024-10318

CVSS V2 None CVSS V3 None
Description
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.
Overview
  • CVE ID
  • CVE-2024-10318
  • Assigner
  • f5
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-06T16:48:56.128Z
  • Last Modified Date
  • 2024-11-06T16:57:40.692Z
References
Reference URL Reference Tags
https://my.f5.com/manage/s/article/K000148232 vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-11-07 13:14:43 Added to TrackCVE