Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-289x-5mj7-xhg5

Опубликовано: 26 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.

EPSS

Процентиль: 24%
0.00321
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.

EPSS

Процентиль: 24%
0.00321
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-613