CVE-2024-10318: F5 Nginx API Connectivity Manager

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.

Affected products

  • F5 Nginx API Connectivity Manager: from 1.3.0, before 1.9.3 (fixed in 1.9.3)
  • F5 Nginx Ingress Controller: up to and including 1.12.5; from 2.2.1, up to and including 2.4.2; from 3.0.0, before 3.7.1 (fixed in 3.7.1)
  • F5 Nginx Instance Manager: from 2.5.0, before 2.17.4 (fixed in 2.17.4)
  • F5 Nginx Openid Connect: before 2024-10-24 (fixed in 2024-10-24)

Published 2024-11-06. Last modified 2026-06-17.