HIGH7.4
GHSA-pj27-2xvp-4qxg
@fastify/session reuses destroyed session cookie
Quick fix
GHSA-pj27-2xvp-4qxg — @fastify/session: upgrade to the fixed version with the command below.
npm install @fastify/session@10.9.0Details
### Impact
When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly detected as expired and thus expired sessions are not destroyed.
### Patches
Updating to v10.9.0 will solve this.
### Workarounds
None
### References
Publicly reported at: https://github.com/fastify/session/issues/251
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/fastify/session/security/advisories/GHSA-pj27-2xvp-4qxg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-35220[ADVISORY]
- https://github.com/fastify/session/issues/251[WEB]
- https://github.com/fastify/session/commit/0495ce5b534c4550f25228821db8098293439f2f[WEB]
- https://github.com/fastify/session[PACKAGE]