Description
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T19:02:49.322Z
Reserved: 2024-02-19T00:00:00.000Z
Link: CVE-2024-26331
Updated: 2024-08-02T00:07:19.211Z
Status : Deferred
Published: 2024-04-30T19:15:23.200
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-26331
No data.
OpenCVE Enrichment
No data.
Weaknesses