Old session tokens can be used to authenticate to the application and send authenticated requests.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://huntr.dev/bounties/35acf263-6db4-4310-ab27-4c3c3a53f796 | patch exploit third party advisory issue tracking |
https://github.com/heroiclabs/nakama/commit/ce8d3921e2acd44ef8b5e6edfe595b6df067b166 | third party advisory patch |