Количество 2
Количество 2
CVE-2021-25979
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.
GHSA-9j9m-8wjc-ff96
Apostrophe CMS Insufficient Session Expiration vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-25979 Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session. | CVSS3: 9.8 | 0% Низкий | больше 4 лет назад | |
GHSA-9j9m-8wjc-ff96 Apostrophe CMS Insufficient Session Expiration vulnerability | CVSS3: 9.8 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу