CVE Vulnerabilities

CVE-2017-1000150

Session Fixation

Published: Nov 03, 2017 | Modified: Nov 13, 2017
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 15.04-rc1 (including) 15.04-rc1 (including)
Mahara Mahara 15.04-rc2 (including) 15.04-rc2 (including)
Mahara Mahara 15.04.0 (including) 15.04.0 (including)
Mahara Mahara 15.04.1 (including) 15.04.1 (including)
Mahara Mahara 15.04.2 (including) 15.04.2 (including)
Mahara Mahara 15.04.3 (including) 15.04.3 (including)
Mahara Mahara 15.04.4 (including) 15.04.4 (including)
Mahara Mahara 15.04.5 (including) 15.04.5 (including)
Mahara Mahara 15.04.6 (including) 15.04.6 (including)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References