CVE-2024-21492

CVSS V2 None CVSS V3 None
Description
All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.
Overview
  • CVE ID
  • CVE-2024-21492
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-17T05:00:03.171Z
  • Last Modified Date
  • 2024-06-04T17:37:40.919Z
History
Created Old Value New Value Data Type Notes
2024-06-26 15:16:27 Added to TrackCVE