Loading
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Use CWE-384, Redhat vendor hub and Wildfly Elytron product page to widen CVE-2020-10714 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-1748, CVE-2022-3143 and CVE-2021-3642 for nearby disclosures in the same product family.