CVE Vulnerabilities

CVE-2022-34624

Insufficient Session Expiration

Published: Aug 19, 2022 | Modified: Aug 23, 2022
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Mealie Mealie 0.5.5 (including) 0.5.5 (including)
Mealie Mealie 1.0.0-beta3 (including) 1.0.0-beta3 (including)

Potential Mitigations

References