Описание
In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect session management.
Ссылки
- Product
- Exploit
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 1.25.0 (исключая)
cpe:2.3:a:gatling:gatling:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 13%
0.00043
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-1259
Связанные уязвимости
CVSS3: 6.5
github
6 месяцев назад
In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect session management.
EPSS
Процентиль: 13%
0.00043
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-1259