You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
com.enonic.xp:lib-auth vulnerable to Session Fixation
Critical severity
GitHub Reviewed
Published
Oct 12, 2022
in
enonic/xp
•
Updated Jan 22, 2026
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Learn more on MITRE.
Impact
All id-providers using lib-auth
loginmethod.Patches
enonic/xp@0189975
enonic/xp@2abac31
enonic/xp@1f44674
Workarounds
Don't use lib-auth for
login.Java API uses low-level structures and allows to invalidate previous session before auth-info is added.
References
enonic/xp#9253
References