GHSA-9j9m-8wjc-ff96

    Dashboard / Vulnerabilities / GHSA-9j9m-8wjc-ff96

    GHSA-9j9m-8wjc-ff96

    Published: 10 Nov 2021Last Modified: 8 Nov 2023

    Summary: Apostrophe CMS Insufficient Session Expiration vulnerability

    Details: Apostrophe CMS versions between 2.63.0 to 3.3.1 affected by an insufficient session expiration vulnerability, which allows unauthenticated remote attackers to hijack recently logged-in users' sessions. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.

    Affected packages

    Package

    Name: apostrophe

    Purl: pkg:npm/apostrophe

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.63.0
    Fixed -3.4.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-9j9m-8wjc-ff96 | CVE-DB