ZeroHour

CVE-2019-10158

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

Vendors
infinispanredhat
Products
infinispan, jboss data grid
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.