First published: Wed Nov 09 2022(Updated: )
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workspace ONE Assist | <22.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31689 has a medium severity rating due to the potential for session fixation attacks.
To fix CVE-2022-31689, upgrade to VMware Workspace ONE Assist version 22.10 or later.
CVE-2022-31689 allows a malicious actor to perform session fixation attacks by using a valid session token.
CVE-2022-31689 affects versions of VMware Workspace ONE Assist prior to 22.10.
Session fixation is a type of attack where an attacker tricks a user into using a specific session ID, which the attacker can then hijack.