Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-24477: NN-2023:8-01 - Session Fixation in Guardian/CMC before 22.6.2 - CVE-2023-24477

In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user’s session.

CVE
#web#auth#chrome

Summary

In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user’s session.

Impact

Unauthorized access.

Affected Products

Guardian, CMC < v22.6.2

Workarounds and Mitigations

Adopt best practices that include closing the browser after a logout.

Solutions

Upgrade to v22.6.2, v23.0.0 or later.

Modification History

2023-08-09: Initial revision

Related Links****Acknowledgements

This issue was confirmed by Nozomi Networks after a bug reported by one of our Customers.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907