Session Fixation In codeigniter/framework
Description
CodeIgniter Session Fixation Vulnerability
A Session Fixation issue exists in CodeIgniter before 3.1.10 because session.use_strict_mode in the Session Library was mishandled.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.1.10 | ||
packagist | 4.0.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.