Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://www.immuta.com/ | product |
https://labs.bishopfox.com/advisories | third party advisory exploit |
https://labs.bishopfox.com/advisories/immuta-version-2.8.2 | third party advisory release notes |