PT-2026-107579 · Apache · Apache Jackrabbit
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Jackrabbit versions 2.23.0 through 2.23.5
Apache Jackrabbit versions 2.22.0 through 2.22.4
Apache Jackrabbit versions 2.20.0 through 2.20.17
Description
The WebDAV server allows session fixation and session reuse across users. The system attaches a cached authenticated session without performing a credential check when a match is found in the
Lock-Token, TransactionId, SubscriptionId, or If-header field tokens. This can lead to a pre-authentication hijack of cached sessions via derivable WebDAV lock tokens.Recommendations
Upgrade versions 2.23.0 through 2.23.5 to 2.23.6.
Upgrade versions 2.22.0 through 2.22.4 to 2.22.5.
Upgrade versions 2.20.0 through 2.20.17 to 2.20.18.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jackrabbit