CVE-2024-10318: NGINX OpenID Connect Vulnerability
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10318?
CVE-2024-10318 is considered a high severity vulnerability due to its potential for session fixation attacks.
How do I fix CVE-2024-10318?
To fix CVE-2024-10318, upgrade to the recommended versions provided in the advisory for affected NGINX products.
Which versions of F5 NGINX products are affected by CVE-2024-10318?
CVE-2024-10318 affects specific versions of F5 NGINX Plus, NGINX Instance Manager, NGINX API Connectivity Manager, and NGINX Ingress Controller as detailed in the advisory.
What is the impact of CVE-2024-10318?
The impact of CVE-2024-10318 allows an attacker to fix a victim's session to an attacker-controlled account, enabling unauthorized actions.
Is there a workaround for CVE-2024-10318?
Currently, there are no recommended workarounds for CVE-2024-10318; upgrading is the primary method of mitigation.