A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.
References
Configurations
No configuration.
History
15 Nov 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 11:15
Updated : 2024-11-15 19:35
NVD link : CVE-2021-3740
Mitre link : CVE-2021-3740
CVE.ORG link : CVE-2021-3740
JSON object : View
Products Affected
No product.
CWE
CWE-384
Session Fixation