Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://huntr.dev/bounties/3080fc96-75d7-4868-84de-9fc8c9b90290 | patch exploit third party advisory issue tracking |
https://github.com/cockpit-hq/cockpit/commit/dd8d0314912fa6517ebd2cc9939d9fafbe68731b | third party advisory patch |