CVE-2020-8990Session Fixation in Digital IBI

CWE-384Session Fixation2 documents2 sources
Severity
9.1CRITICALNVD
EPSS
0.3%
top 50.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 24

Description

Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-rrvx-f88m-c779: Western Digital My Cloud Home before 32022-05-24