Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://huntr.dev/bounties/67c25969-5e7a-4424-817e-e1a918f63cc6 | third party advisory exploit patch |
https://github.com/ikus060/rdiffweb/commit/39e7dcd4a1f44d2a7bd92b79d78a800910b1b22b | third party advisory patch |