Uploaded image for project: 'Crowd'
  1. Crowd
  2. CWD-5361

Insufficient Session Expiration of user sessions - CVE-2018-20238

    XMLWordPrintable

    Details

      Description

      Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned
              Reporter:
              security-metrics-bot SecurityB
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: