Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-5361

Insufficient Session Expiration of user sessions - CVE-2018-20238

      Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

            [CWD-5361] Insufficient Session Expiration of user sessions - CVE-2018-20238

            Said made changes -
            Labels Original: CVE-2018-20238 advisory advisory-released security New: CVE-2018-20238 advisory advisory-released basm insufficient-session-expiration security
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 3100826 ] New: JAC Bug Workflow v3 [ 3365948 ]
            Oleksandr Tkachenko made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 416689 ]
            David Black made changes -
            Labels Original: advisory advisory-released security New: CVE-2018-20238 advisory advisory-released security
            David Black made changes -
            Summary Original: Insufficient Session Expiration of user sessions New: Insufficient Session Expiration of user sessions - CVE-2018-20238
            David Black made changes -
            Description Original: Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired session via an insufficient session expiration vulnerability. New: Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
            David Black made changes -
            Labels Original: advisory advisory-to-release security New: advisory advisory-released security
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Fix Version/s New: 3.4.0 [ 82291 ]
            David Black made changes -
            Remote Link New: This issue links to "KRAK-1774 (JIRA Server (Bulldog))" [ 411300 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: