VDB
Sign up
MEDIUM4.6

GHSA-7rg2-qxmf-hhx9

Session fixation in express-openid-connect

Quick fix

GHSA-7rg2-qxmf-hhx9 — express-openid-connect: upgrade to the fixed version with the command below.

npm install express-openid-connect@2.5.2

Details

### Overview

Versions `2.3.0` up to and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities.

### Am I affected? You are affected by this vulnerability if you are using `express-openid-connect` version `2.3.0` up to and including `2.5.1` and use a custom session store.

### How to fix that? Upgrade to version `>= 2.5.2`.

### Will this update impact my users? The fix provided in patch will not affect your users.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-openid-connect
Introduced in: 2.3.0Fixed in: 2.5.2
Fixnpm install express-openid-connect@2.5.2

References