Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-23679.json"