{"id":"BIT-silverstripe-2022-24444","details":"Silverstripe silverstripe/framework through 4.10 allows Session Fixation.","aliases":["CVE-2022-24444","GHSA-c7q8-m4xw-c674"],"modified":"2024-03-06T11:25:28.861Z","published":"2024-03-06T11:05:09.100Z","database_specific":{"cpes":["cpe:2.3:a:silverstripe:silverstripe:*:*:*:*:*:*:*:*","cpe:2.3:a:silverstripe:silverstripe:2.5.0:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://docs.silverstripe.org/en/4/changelogs/4.10.1/"},{"type":"WEB","url":"https://forum.silverstripe.org/c/releases"},{"type":"WEB","url":"https://www.silverstripe.org/blog/tag/release"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/cve-2022-24444"}],"affected":[{"package":{"name":"silverstripe","ecosystem":"Bitnami","purl":"pkg:bitnami/silverstripe"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.4.0"}]},{"type":"SEMVER","events":[{"introduced":"2.5.0"},{"last_affected":"2.5.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/silverstripe/BIT-silverstripe-2022-24444.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}],"schema_version":"1.7.3"}