A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
F5
F5 nginx Api Connectivity Manager F5 nginx Ingress Controller F5 nginx Instance Manager F5 nginx Openid Connect |
|
CPEs | cpe:2.3:a:f5:nginx_api_connectivity_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_openid_connect:*:*:*:*:*:nginx_plus:*:* |
|
Vendors & Products |
F5
F5 nginx Api Connectivity Manager F5 nginx Ingress Controller F5 nginx Instance Manager F5 nginx Openid Connect |
Thu, 07 Nov 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 06 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 06 Nov 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session. | |
Title | NGINX OpenID Connect Vulnerability | |
Weaknesses | CWE-384 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: f5
Published: 2024-11-06T16:48:56.128Z
Updated: 2024-11-06T16:57:40.692Z
Reserved: 2024-10-23T19:34:33.203Z
Link: CVE-2024-10318
Vulnrichment
Updated: 2024-11-06T16:57:37.077Z
NVD
Status : Analyzed
Published: 2024-11-06T17:15:13.680
Modified: 2024-11-08T19:51:49.380
Link: CVE-2024-10318
Redhat