Description
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set.
This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This vulnerability has been patched 10.8.0.
This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This vulnerability has been patched 10.8.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1716 | @fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed. This vulnerability has been patched 10.8.0. |
Github GHSA |
GHSA-pj27-2xvp-4qxg | @fastify/session reuses destroyed session cookie |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:07:46.810Z
Reserved: 2024-05-14T15:39:41.783Z
Link: CVE-2024-35220
Updated: 2024-08-02T03:07:46.810Z
Status : Awaiting Analysis
Published: 2024-05-21T21:15:08.117
Modified: 2024-11-21T09:19:57.883
Link: CVE-2024-35220
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA