CVE-2021-41246
2.3.0
up to and including 2.5.1
do not regenerate the session id and when user logs in. This behavior opens up the application to various session fixation vulnerabilities.
express-openid-connect
version 2.3.0
up to and including 2.5.1
and use a custom session store.
>= 2.5.2