rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pretix | Rami | 1.16.0 (including) | 4.15.1 (excluding) |
Pretix | Rami | 4.16.0 (including) | 4.16.0 (including) |
Pretix | Rami | 4.17.0 (including) | 4.17.0 (including) |