Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3gq-f9rc-qmwx

Опубликовано: 06 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365.

The user will stay authenticated until the Devolutions Server token expiration.

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365.

The user will stay authenticated until the Devolutions Server token expiration.

EPSS

Процентиль: 24%
0.0008
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.5
nvd
почти 2 года назад

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365. The user will stay authenticated until the Devolutions Server token expiration.

EPSS

Процентиль: 24%
0.0008
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-613