CVE-2023-0227
Vulnerability Description
Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.
Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to l...
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
Old session tokens can be used to authenticate to the application and send authenticated requests.
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several tim...
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and activ...
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.