CVE-2016-8638
Last modified
CVE-2016-8638 is a vulnerability of currently unknown severity. A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. EPSS estimates a 2.12% chance of exploitation in the next 30 days.
Description
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ipsilon Project | Ipsilon | 1.0.0 |
| Ipsilon Project | Ipsilon | 1.0.1 |
| Ipsilon Project | Ipsilon | 1.0.2 |
| Ipsilon Project | Ipsilon | 1.1.0 |
| Ipsilon Project | Ipsilon | 1.1.1 |
| Ipsilon Project | Ipsilon | 1.2.0 |
| Ipsilon Project | Ipsilon | 2.0.0 |
| Ipsilon Project | Ipsilon | 2.0.1 |
References
- http://www.securityfocus.com/bid/94439Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8638Issue Tracking, Third Party Advisory
- https://ipsilon-project.org/advisory/CVE-2016-8638.txtVendor Advisory
- https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461cPatch, Vendor Advisory
- http://www.securityfocus.com/bid/94439Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8638Issue Tracking, Third Party Advisory
- https://ipsilon-project.org/advisory/CVE-2016-8638.txtVendor Advisory
- https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461cPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8638?
How severe is CVE-2016-8638?
How do I fix CVE-2016-8638?
Are you affected by CVE-2016-8638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
