An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2768 An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 21 May 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Optimizely
Optimizely configured Commerce
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*
Vendors & Products Optimizely
Optimizely configured Commerce

Mon, 06 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jan 2025 02:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.
Weaknesses CWE-598
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-06T17:01:10.261Z

Reserved: 2025-01-04T00:00:00

Link: CVE-2025-22387

cve-icon Vulnrichment

Updated: 2025-01-06T17:01:02.795Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-04T02:15:07.343

Modified: 2025-05-21T17:05:51.227

Link: CVE-2025-22387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.