CVE-2024-58317

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*

History

24 Dec 2025, 16:38

Type Values Removed Values Added
First Time Kentico
Kentico xperience
CPE cpe:2.3:a:kentico:xperience:*:*:*:*:*:*:*:*
References () https://devnet.kentico.com/download/hotfixes - () https://devnet.kentico.com/download/hotfixes - Product
References () https://www.vulncheck.com/advisories/kentico-xperience-cookie-security-configuration - () https://www.vulncheck.com/advisories/kentico-xperience-cookie-security-configuration - Third Party Advisory

18 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 20:15

Updated : 2025-12-24 16:38


NVD link : CVE-2024-58317

Mitre link : CVE-2024-58317

CVE.ORG link : CVE-2024-58317


JSON object : View

Products Affected

kentico

  • xperience
CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute