Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mahara:mahara:15.04:rc1:*:*:*:*:*:*", "matchCriteriaId": "DCE2F6EE-06BE-4665-BA7B-AB6C97DAE02D", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04:rc2:*:*:*:*:*:*", "matchCriteriaId": "313A5DDA-204F-4ED3-BE22-FA0D8A239BC7", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.0:*:*:*:*:*:*:*", "matchCriteriaId": "6932E7F9-BA51-4099-8987-8944E0284B7B", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.1:*:*:*:*:*:*:*", "matchCriteriaId": "022D7031-54EF-484C-B076-15C4342532E3", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.2:*:*:*:*:*:*:*", "matchCriteriaId": "6FFB08C5-151E-49D2-AC13-1018FF402569", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.3:*:*:*:*:*:*:*", "matchCriteriaId": "853E7231-70C7-4A1F-817F-E43D78BCB060", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.4:*:*:*:*:*:*:*", "matchCriteriaId": "96E14503-4E8B-44F5-9CAB-EF074CA71862", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.5:*:*:*:*:*:*:*", "matchCriteriaId": "9AD7E980-E0C1-44D1-AFDE-F47CE3A48C71", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.04.6:*:*:*:*:*:*:*", "matchCriteriaId": "9C9623EF-7C2D-4A58-AF56-DBD8707CC9EE", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mahara:mahara:15.10.0:*:*:*:*:*:*:*", "matchCriteriaId": "609A3054-6DA9-44A8-9927-29E181D4D07F", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.10.1:*:*:*:*:*:*:*", "matchCriteriaId": "E5E8584F-8CD3-415C-BFC0-DC825089CA42", "vulnerable": true}, {"criteria": "cpe:2.3:a:mahara:mahara:15.10.2:*:*:*:*:*:*:*", "matchCriteriaId": "023729FA-BEA6-4D89-87B3-C91A7FBDDD46", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks."}, {"lang": "es", "value": "Mahara, en versiones 15.04 anteriores a la 15.04.7 y versiones 15.10 anteriores a la 15.10.3, es vulnerable a que se evite que los ID de sesi\u00f3n se regeneren en el inicio o el cierre de sesi\u00f3n. Esto hace que los usuarios del sitio sean m\u00e1s vulnerables a ataques de fijaci\u00f3n de sesi\u00f3n."}], "id": "CVE-2017-1000150", "lastModified": "2025-04-20T01:37:25.860", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 6.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2017-11-03T18:29:00.903", "references": [{"source": "cve@mitre.org", "tags": ["Issue Tracking", "Patch", "Third Party Advisory"], "url": "https://bugs.launchpad.net/mahara/+bug/1567784"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Issue Tracking", "Patch", "Third Party Advisory"], "url": "https://bugs.launchpad.net/mahara/+bug/1567784"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-384"}], "source": "nvd@nist.gov", "type": "Primary"}]}