Description
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to insecure authentication and session management.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Subscribe Cross-Site Scripting (1.0.2)
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)
Oracle JRE CVE-2013-5824 Vulnerability (CVE-2013-5824)
PleskWin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-0132)