CVE-2024-23679
Critical · CVSS 9.8Enonic XP (com.enonic.xp:lib-auth) — Session Fixation (CWE-384) - lack of session invalidation on authentication
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-384, CWE-384
Description
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
Search profile — drives PoC discovery
Symbols lib-authcom.enonic.xpsession fixationinvalidateSessionsessionAttributeslib-auth loginHttpSessionsession.invalidateGHSA-4m5p-5w5w-3jcf
Keywords CVE-2024-23679Enonic XP session fixationcom.enonic.xp lib-authEnonic XP unauthenticated session reuseEnonic XP 7.7.4 vulnerabilityGHSA-4m5p-5w5w-3jcf PoCEnonic XP session invalidation bypassenonic xp CVE-2024-23679 exploit
Versions: < 7.7.4
Affected packages
| Maven | com.enonic.xp:lib-auth | 0 → 7.7.4 |
References
- https://github.com/advisories/GHSA-4m5p-5w5w-3jcf
- https://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff
- https://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4
- https://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842
- https://github.com/enonic/xp/issues/9253
- https://github.com/enonic/xp/security/advisories/GHSA-4m5p-5w5w-3jcf
- https://vulncheck.com/advisories/vc-advisory-GHSA-4m5p-5w5w-3jcf
- https://github.com/advisories/GHSA-4m5p-5w5w-3jcf
- https://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff
- https://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4
- https://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842
- https://github.com/enonic/xp/issues/9253
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z