CVE Vulnerabilities

CVE-2020-15950

Insufficient Session Expiration

Published: Nov 05, 2020 | Modified: Nov 12, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Immuta Immuta 2.8.2 (including) 2.8.2 (including)

Potential Mitigations

References