Vulnerabilities > CVE-2021-3311 - Insufficient Session Expiration vulnerability in Octobercms October

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.

Vulnerable Configurations

Part Description Count
Application
Octobercms
366

Common Weakness Enumeration (CWE)