CVE-2016-8638
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- ipsilon project/ipsilon
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2809.html
- http://www.securityfocus.com/bid/94439Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8638Issue Tracking, Third Party Advisory
- https://ipsilon-project.org/advisory/CVE-2016-8638.txtVendor Advisory
- https://ipsilon-project.org/release/2.1.0.html
- https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461cPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2809.html
- http://www.securityfocus.com/bid/94439Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8638Issue Tracking, Third Party Advisory
- https://ipsilon-project.org/advisory/CVE-2016-8638.txtVendor Advisory
- https://ipsilon-project.org/release/2.1.0.html
- https://pagure.io/ipsilon/c/511fa8b7001c2f9a42301aa1d4b85aaf170a461cPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.