Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fm4w-5hqf-ch9w

Опубликовано: 10 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.

EPSS

Процентиль: 53%
0.00305
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.

EPSS

Процентиль: 53%
0.00305
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384