Improper session-affinity settings can enable session fixation or hijacking across backend targets.
Networking / Loadbalancer / Threats / DEV
Session Persistence Is Exploited
CCC.LB.TH04
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.LB.CP15 | Session Affinity | Can configure subsequent requests from an initial client to be passed to the same target. |
Related Controls
| ID | Title | Description |
|---|---|---|
| CCC.LB.CN05 | Validate Session Affinity | Configure session persistence to minimise fixation and hijacking risks. |