Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:CWD-5361
HistoryFeb 13, 2019 - 12:37 a.m.

Insufficient Session Expiration of user sessions - CVE-2018-20238

2019-02-1300:37:34
security-metrics-bot
jira.atlassian.com
178

EPSS

0.002

Percentile

53.5%

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

EPSS

0.002

Percentile

53.5%

Related for ATLASSIAN:CWD-5361