CVE Vulnerabilities

CVE-2023-45659

Insufficient Session Expiration

Published: Oct 17, 2023 | Modified: Oct 30, 2023
CVSS 3.x
2.8
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Engelsystem is a shift planning system for chaos events. If a users password is compromised and an attacker gained access to a users account, i.e., logged in and obtained a session, an attackers session is not terminated if the users account password is reset. This vulnerability has been fixed in the commit dbb089315ff3d. Users are advised to update their installations. There are no known workarounds for this vulnerability.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Engelsystem Engelsystem * 2023-09-18 (excluding)

Potential Mitigations

References