CVE Vulnerabilities

CVE-2020-27422

Insufficient Session Expiration

Published: Nov 16, 2020 | Modified: Nov 30, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesnt expire once used, allowing an attacker to use the same link to takeover the account.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Time_tracker Anuko * 1.19.23.5311 (including)

Potential Mitigations

References