PT-2025-22515 · Wire · Wire-Webapp
Published
2025-05-22
·
Updated
2025-05-22
·
CVE-2025-48061
CVSS v3.1
5.6
Medium
| Vector | AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wire-webapp versions 2025-05-14-production.0 through 2025-05-20-production.0
Description
The issue is related to a regression in the session invalidation process. When a user logs out of the Wire webapp, they could be automatically logged in again after re-opening the application. This behavior does not occur when the user logs in as a temporary user or selects the option to delete all personal information and conversations upon logout.
Recommendations
For wire-webapp versions 2025-05-14-production.0 through 2025-05-20-production.0, update to version 2025-05-20-production.0 to resolve the issue.
As a temporary workaround, consider deleting all information upon logout or logging in as a temporary client to prevent automatic login.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wire-Webapp