PT-2008-2976 · Plone Foundation · Plone Cms

Adrian Pastor

+2

·

Publicado

2008-03-20

·

Atualizado

2018-10-11

·

CVE-2008-1395

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Plone CMS (affected versions not specified)
Description The issue concerns the handling of user authentication states. Specifically, it does not record users' authentication states and implements the logout feature solely on the client side. This makes it easier for context-dependent attackers to reuse a logged-out session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1395

Produtos afetados

Plone Cms