-
Bug
-
Resolution: Fixed
-
High
-
3.2.0, 3.2.1, 3.2.3, 3.3.0, 3.2.4, 3.2.5, 3.3.1, 3.2.6, 3.3.3
-
None
-
Severity 2 - Major
-
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 8.1 => High severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N