Published: December 08, 2021 CVE number:Documentation Index
Fetch the complete documentation index at: https://docs-staging.auth0-mintlify.app/llms.txt
Use this file to discover all available pages before exploring further.
CVE-2021-41246
Overview
Versions2.3.0 up to and including 2.5.1 do not regenerate the session id and when user logs in. This behavior opens up the application to various session fixation vulnerabilities.
Am I affected?
You are affected by this vulnerability if you are usingexpress-openid-connect version 2.3.0 up to and including 2.5.1 and use a custom session store.
How to fix that?
Upgrade to version>= 2.5.2