Vulnerabilities > CVE-2022-34624 - Insufficient Session Expiration vulnerability in Mealie 0.5.5/1.0.0
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |