PT-2023-25348 · Unknown · Siren Investigate
Published
2023-06-19
·
Updated
2023-06-27
·
CVE-2023-35857
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Siren Investigate versions prior to 13.2.2
Description
The issue concerns session keys remaining active even after a user logs out. This could potentially allow unauthorized access to user sessions.
Recommendations
For versions prior to 13.2.2, update to version 13.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources or implementing additional authentication measures to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siren Investigate