Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8pm-g6v2-5wgx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The vulnerability can be described as a failure to invalidate user session upon password change. When running multiple active sessions in separate browser windows, it was observed a password or email address change could be changed without terminating the user session.

The vulnerability can be described as a failure to invalidate user session upon password change. When running multiple active sessions in separate browser windows, it was observed a password or email address change could be changed without terminating the user session.

EPSS

Процентиль: 48%
0.00248
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 4.8
nvd
больше 4 лет назад

The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email address change. When running multiple active sessions in separate browser windows, it was observed a password or email address change could be changed without terminating the user session. This issue has been resolved on September 13, 2021.

EPSS

Процентиль: 48%
0.00248
Низкий

Дефекты

CWE-613