Lucene search

K
osvGoogleOSV:GHSA-4JFQ-F8HC-775Q
HistoryMay 24, 2022 - 5:41 p.m.

Magento Insufficient Session Expiration

2022-05-2417:41:56
Google
osv.dev
5
magento
session expiration
unauthorized access
security issue

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

68.0%

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead to unauthorized access to restricted resources. Access to the admin console is not required for successful exploitation.

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

68.0%

Related for OSV:GHSA-4JFQ-F8HC-775Q