{"id":"GHSA-4m5p-5w5w-3jcf","summary":"com.enonic.xp:lib-auth vulnerable to Session Fixation","details":"### Impact\nAll id-providers using lib-auth `login` method.\n\n### Patches\nhttps://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff\nhttps://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842\nhttps://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4\n\n### Workarounds\nDon't use lib-auth for `login`. \nJava API uses low-level structures and allows to invalidate previous session before auth-info is added.\n\n### References\n\nhttps://github.com/enonic/xp/issues/9253","aliases":["CVE-2024-23679"],"modified":"2026-07-08T06:52:59.258449095Z","published":"2022-10-12T20:13:46Z","database_specific":{"github_reviewed_at":"2022-10-12T20:13:46Z","nvd_published_at":null,"cwe_ids":["CWE-384"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/enonic/xp/security/advisories/GHSA-4m5p-5w5w-3jcf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23679"},{"type":"WEB","url":"https://github.com/enonic/xp/issues/9253"},{"type":"WEB","url":"https://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff"},{"type":"WEB","url":"https://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4"},{"type":"WEB","url":"https://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842"},{"type":"PACKAGE","url":"https://github.com/enonic/xp"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-4m5p-5w5w-3jcf"}],"affected":[{"package":{"name":"com.enonic.xp:lib-auth","ecosystem":"Maven","purl":"pkg:maven/com.enonic.xp/lib-auth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}