CVE Vulnerabilities

CVE-2024-29070

Insufficient Session Expiration

Published: Jul 23, 2024 | Modified: Jul 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns Authorization as the front-end authentication credential. Authorization can still initiate requests and access data even after logout.

Mitigation:

all users should upgrade to 2.1.4

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Streampark Apache 1.0.0 (including) 2.1.4 (excluding)

Potential Mitigations

References