Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9j9m-8wjc-ff96

Опубликовано: 10 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apostrophe CMS Insufficient Session Expiration vulnerability

Apostrophe CMS versions between 2.63.0 to 3.3.1 affected by an insufficient session expiration vulnerability, which allows unauthenticated remote attackers to hijack recently logged-in users' sessions. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.

Пакеты

Наименование

apostrophe

npm
Затронутые версииВерсия исправления

>= 2.63.0, < 3.4.0

3.4.0

EPSS

Процентиль: 58%
0.00363
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.

EPSS

Процентиль: 58%
0.00363
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613