First published: Mon May 27 2019(Updated: )
A vulnerability was found in Infinispan up to version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration may result in an incorrect session handling Referrences: <a href="https://issues.jboss.org/browse/ISPN-10224">https://issues.jboss.org/browse/ISPN-10224</a> Upstream Patch: <a href="https://github.com/infinispan/infinispan/pull/6960">https://github.com/infinispan/infinispan/pull/6960</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Infinispan | <=9.4.14.Final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1714359 is considered to be moderate due to improper session handling.
To fix REDHAT-BUG-1714359, upgrade Infinispan to a version later than 9.4.14.Final.
Infinispan versions up to and including 9.4.14.Final are affected by REDHAT-BUG-1714359.
The vulnerability in REDHAT-BUG-1714359 involves improper implementation of session fixation protection.
Yes, REDHAT-BUG-1714359 is related to an improper session handling in the Spring Session integration.