CVE-2024-35220

CVSS V2 None CVSS V3 None
Description
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This vulnerability has been patched 10.8.0.
Overview
  • CVE ID
  • CVE-2024-35220
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-21T20:26:53.312Z
  • Last Modified Date
  • 2024-06-04T17:34:24.350Z
History
Created Old Value New Value Data Type Notes
2024-06-26 14:02:08 Added to TrackCVE