CVE-2024-56529

Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.
Configurations

No configuration.

History

No history.

Information

Published : 2025-01-28 23:15

Updated : 2025-03-14 17:15


NVD link : CVE-2024-56529

Mitre link : CVE-2024-56529

CVE.ORG link : CVE-2024-56529


JSON object : View

Products Affected

No product.

CWE
CWE-384

Session Fixation