MEDIUM4.6
GHSA-7rg2-qxmf-hhx9
Session fixation in express-openid-connect
Quick fix
GHSA-7rg2-qxmf-hhx9 — express-openid-connect: upgrade to the fixed version with the command below.
npm install express-openid-connect@2.5.2Details
### Overview
Versions `2.3.0` up to and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities.
### Am I affected? You are affected by this vulnerability if you are using `express-openid-connect` version `2.3.0` up to and including `2.5.1` and use a custom session store.
### How to fix that? Upgrade to version `>= 2.5.2`.
### Will this update impact my users? The fix provided in patch will not affect your users.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/express-openid-connect
Introduced in:
2.3.0Fixed in: 2.5.2Fix
npm install express-openid-connect@2.5.2References
- https://github.com/auth0/express-openid-connect/security/advisories/GHSA-7rg2-qxmf-hhx9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41246[ADVISORY]
- https://github.com/auth0/express-openid-connect/commit/5ab67ff2bd84f76674066b5e129b43ab5f2f430f[WEB]
- https://github.com/auth0/express-openid-connect[PACKAGE]
- https://github.com/auth0/express-openid-connect/releases/tag/v2.5.2[WEB]