CVE-2024-21492
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 17, 2024
Updated: Feb 20, 2024
CWE ID 613
Summary
CVE-2024-21492: This vulnerability affects all versions of the github.com/greenpau/caddy-security package. The issue lies in the improper session invalidation upon clicking the "Sign Out" button. Although requests are sent to /logout and /oauth2/google/logout, user sessions remain valid. Attackers can exploit this vulnerability by gaining access to an active but supposedly logged-out session, enabling them to perform unauthorized actions on behalf of the user.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share