Vulnerability Description
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-56529?
CVE-2024-56529 is a vulnerability with a CVSS score of 7.1 (HIGH). Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in...
How severe is CVE-2024-56529?
CVE-2024-56529 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-56529?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.