Uploaded image for project: 'Crowd'
  1. Crowd
  2. CWD-5361

Insufficient Session Expiration of user sessions - CVE-2018-20238

    XMLWordPrintable

    Details

      Description

      Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                security-metrics-bot SecurityB
                Participants:
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Last commented:
                  18 weeks, 6 days ago