Vulnerabilities > CVE-2021-3311 - Insufficient Session Expiration vulnerability in Octobercms October
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://anisiosantos.me/october-cms-token-reactivation
- https://anisiosantos.me/october-cms-token-reactivation
- https://github.com/octobercms/library/commit/642f597489e6f644d4bd9a0c267e864cabead024
- https://github.com/octobercms/library/commit/642f597489e6f644d4bd9a0c267e864cabead024
- https://octobercms.com/forum/chan/announcements
- https://octobercms.com/forum/chan/announcements