Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID
for a victim and later hijack the authenticated session.
This issue was fixed in version 3.17.2.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2. | |
| Title | Session Fixation in Bludit | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-03-27T11:55:08.924Z
Updated: 2026-03-27T12:44:09.658Z
Reserved: 2026-01-29T12:40:23.880Z
Link: CVE-2026-25101
Updated: 2026-03-27T12:44:03.276Z
Status : Received
Published: 2026-03-27T12:16:20.203
Modified: 2026-03-27T12:16:20.203
Link: CVE-2026-25101
No data.