Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-21492
HistoryFeb 17, 2024 - 5:15 a.m.

Session fixation

2024-02-1705:15:00
PRIOn knowledge base
www.prio-n.com
7
session fixation
session expiration
user session invalidation
sign out
logout
oauth2
google
unauthorized actions
nvd

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the “Sign Out” button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Related for PRION:CVE-2024-21492