Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jw2-24wg-vcf7

Опубликовано: 04 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

EPSS

Процентиль: 84%
0.02105
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

EPSS

Процентиль: 84%
0.02105
Низкий

Дефекты

CWE-613