CVE-2024-10318 Information

Description

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation where a nonce was not checked at login time. This flaw allows an attacker to fix a victim’s session to an attacker-controlled account. As a result although the attacker cannot log in as the victim they can force the session to associate it with the attacker-controlled account leading to potential misuse of the victim’s session.

Reference

https://my.f5.com/manage/s/article/K000148232

Share on: