// For flags

CVE-2020-10714

wildfly-elytron: session fixation when using FORM authentication

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Se encontró un fallo en versión 1.11.3.Final y anteriores de WildFly Elytron. Cuando se usa la autenticación FORM de WildFly Elytron con un ID de sesión en la URL, un atacante podría llevar a cabo un ataque de fijación de sesión. La mayor amenaza de esta vulnerabilidad es la confidencialidad e integridad de los datos, así como la disponibilidad del sistema

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-03-20 CVE Reserved
  • 2020-08-17 CVE Published
  • 2023-06-09 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-384: Session Fixation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Wildfly Elytron
Search vendor "Redhat" for product "Wildfly Elytron"
< 1.11.3
Search vendor "Redhat" for product "Wildfly Elytron" and version " < 1.11.3"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Studio
Search vendor "Redhat" for product "Codeready Studio"
12.0
Search vendor "Redhat" for product "Codeready Studio" and version "12.0"
-
Affected
Redhat
Search vendor "Redhat"
Descision Manager
Search vendor "Redhat" for product "Descision Manager"
7.0
Search vendor "Redhat" for product "Descision Manager" and version "7.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Fuse
Search vendor "Redhat" for product "Jboss Fuse"
7.0.0
Search vendor "Redhat" for product "Jboss Fuse" and version "7.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Process Automation
Search vendor "Redhat" for product "Process Automation"
7.0
Search vendor "Redhat" for product "Process Automation" and version "7.0"
-
Affected
Netapp
Search vendor "Netapp"
Oncommand Insight
Search vendor "Netapp" for product "Oncommand Insight"
--
Affected