GHSA-7ggw-h8pp-r95r
CRITICALCVE-2021-3311When logging out, the session ID was not invalidated. This is not a problem while the user is logged out, but as soon as the user logs back in the old session ID would be valid again; which means that anyone that gained access to the old session cookie would be able to act as the logged in user. This is not a major concern for the majority of cases, since it requires a malicious party gaining acce
- Affected
- < 1.0.472, >= 1.1.0, < 1.1.2
- Fixed in
- 1.0.472
- Weakness
- CWE-613
- Published
- 2021-02-10
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference