Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwmm-p4j4-8398

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

EPSS

Процентиль: 30%
0.00113
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 1.8
redhat
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 4.4
nvd
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.

CVSS3: 4.4
debian
больше 6 лет назад

A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies ...

CVSS3: 6
fstec
больше 6 лет назад

Уязвимость сервера FreeIPA, связанная с неверным сроком действия сеанса, позволяющая нарушителю получить доступ к сеансу

EPSS

Процентиль: 30%
0.00113
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-613