Review reviewHigh
CVE-2022-27305
gibbon
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
- CVSS
- 8.8
- EPSS
- 0.86% 55.1% percentile
- CISA KEV
- Not listed
- Published
- 2022.05.26