Session Fixation In org.springframework:spring-core
Description
Moderate severity vulnerability that affects org.springframework:spring-core The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 4.1.5 | ||
maven | 4.1.5.release |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.