In Siren Investigate before 13.2.2, session keys remain active even after logging out.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://community.siren.io/c/announcements | release notes |
https://docs.support.siren.io/siren-platform-user-guide/13.2/release-notes.html | release notes |