CVE-2025-34412 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that does not require user action.
A vulnerability exists in the Convercent Whistleblowing Platform, managed by EQS Group, due to a failure in session and browser handling mechanisms. Affected deployments typically lack essential HTTP security headers, such as Content-Security-Policy and Referrer-Policy, and have inadequate clickjacking defenses. Additionally, the platform issues session cookies with insecure or inconsistent attributes, including duplicate ASP.NET_SessionId values, an affinity cookie without the Secure attribute, and mixed or absent SameSite settings. These vulnerabilities compromise session integrity and browser-side isolation, heightening the risk of client-side attacks, session fixation, and cross-site session leakage.
Convercent should implement modern security headers, revise its HSTS configuration, ensure proper session cookie management, enhance clickjacking protections, and address the customer enumeration vulnerability by securing the API endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Dec 24, 2025 | CVE Rejected | [email protected] |
| Dec 24, 2025 | CVE Modified | [email protected] |
| Dec 24, 2025 | CVE Modified | [email protected] |
| Dec 15, 2025 | New CVE Received | [email protected] |