Session Fixation
CVE-2020-8990
Summary
Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-384 - Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
References
Advisory Timeline
- Published