Impact
Session fixation in the HTTP management authentication flow allows remote actors to reuse a session identifier after a successful login, granting them unauthorized access to an administrative session. The flaw is identified as CWE-384 and can be exploited by an attacker who can obtain a valid session cookie and then reuse it to perform actions on the broker that require authentication.
Affected Systems
Apache Qpid Broker-J from the Apache Software Foundation is affected through version 10.1.0. The vulnerability impacts all deployments running any of these releases until the patch for 10.1.1 is applied.
Risk and Exploitability
EPSS data is not available and the flaw is not listed in the CISA KEV catalog, so the public exploitation probability is unknown. The vulnerability permits a remote attacker who can reach the broker's HTTP management port to hijack an authenticated session by reusing a session token. No CVSS score is provided, but the fact that full administrative control becomes possible makes the risk significant. The attack vector is inferred to be remote over HTTP, requiring an attacker to authenticate first and then reuse the session ID.
OpenCVE Enrichment