rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pretix | Rami | 1.16.0 (including) | 4.15.1 (excluding) |
| Pretix | Rami | 4.16.0 (including) | 4.16.0 (including) |
| Pretix | Rami | 4.17.0 (including) | 4.17.0 (including) |