CVE-2023-4320

CVSS v3 Score
7.5
High

Vulnerability Description

An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.

CVSS:7.5(High)

The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.

CVSS:7.5(High)

The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

CVSS:7.5(High)

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible i...

CVSS:7.5(High)

In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.

CVSS:7.5(High)

In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.

CVSS:7.5(High)

Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.