CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-10318

High Severity
F5
SVRS
53/100

CVSSv3
5.4/10

EPSS
0.0006/1

CVE-2024-10318 reveals a session fixation vulnerability in the NGINX OpenID Connect reference implementation, posing a risk to user session security. Specifically, the absence of nonce verification during login allows attackers to bind a victim's session to an attacker-controlled account. With an SVRS score of 53, indicating a moderate risk, immediate patching is not critical but recommended. This flaw, though not enabling direct login as the victim, can lead to session hijacking, unauthorized access, and potentially misuse of the victim's privileges. The vulnerability underscores the need for robust session management and authentication practices in web applications. Addressing this vulnerability is essential to mitigate potential risks. While the CVSS score is 5.4, the SVRS score helps prioritize remediation efforts based on real-world threat context.

No tags available
CVSS:3.1
AV:N
AC:L
PR:N
UI:R
S:U
C:L
I:L
A:N
2024-11-06

2024-11-08

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

2️⃣ In #NGINX OpenID Connect, a session fixation vulnerability affects multiple versions, allowing attackers to hijack victim sessions. As there's no fix yet, stay alert for updates (Reference: CVE-2024-10318).
1
0
0
『An attacker may be able to force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.』 K000148232: NGINX OpenID Connect vulnerability CVE-2024-10318 https://t.co/rY24uGVcu8 iocs: https://my.f5.com/manage/s/article/K000148232
0
0
1
CVE-2024-10318 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacke… https://t.co/NEFIyiFJXb
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppF5nginx_ingress_controller
AppF5nginx_instance_manager
AppF5nginx_api_connectivity_manager

References

ReferenceLink
[email protected]https://my.f5.com/manage/s/article/K000148232

CWE Details

CWE IDCWE NameDescription
CWE-384Session FixationAuthenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence