Severity: important 

Affected versions:

- Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) 
through 10.1.0

Description:

Session fixation in HTTP management authentication allows remoteĀ attackers to 
gain unauthorized access to an authenticated management session via reuse of a 
session identifier retained across successful authentication.

This issue affects Apache Qpid Broker-J: through 10.1.0.

Users are recommended to upgrade to version 10.1.1, which fixes the issue.

Credit:

Abhishek Kushwaha (reporter)

References:

https://qpid.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-92609

Reply via email to