Drupal Session Fixation Vulnerability - SA-2008-046 - Vulnerability Database

Drupal Session Fixation Vulnerability - SA-2008-046

Low
Reference: SA-2008-046
Title: Drupal Session Fixation Vulnerability
Overview:

When contributed modules such as Workflow NG terminate the current request during a login event user module is not able to regenerate the users session. This may lead to a session fixation attack when a malicious user is able to control another users initial session ID. As the session is not regenerated the malicious user may use the fixed session ID after the victim authenticates and will have the same access. Vulnerability ID: SA-2008-046 Official Reference: https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2008-07-23/sa-2008-046-drupal-core-session