Show filters
103 Total Results
Displaying 21-30 of 103
Sort by:
Attacker Value
Unknown
CVE-2020-29012
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain that session ID (via other, hypothetical attacks)
0
Attacker Value
Unknown
CVE-2021-39113
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
0
Attacker Value
Unknown
CVE-2021-35342
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
0
Attacker Value
Unknown
CVE-2021-30943
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An issue in the handling of group membership was resolved with improved logic. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1. A malicious user may be able to leave a messages group but continue to receive messages in that group.
0
Attacker Value
Unknown
CVE-2021-37693
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.
0
Attacker Value
Unknown
CVE-2021-37156
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
0
Attacker Value
Unknown
CVE-2021-33322
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.
0
Attacker Value
Unknown
CVE-2021-20431
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.
0
Attacker Value
Unknown
CVE-2021-26037
Disclosure Date: July 06, 2021 (last updated February 22, 2025)
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
0
Attacker Value
Unknown
CVE-2021-20378
Disclosure Date: July 06, 2021 (last updated February 23, 2025)
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
0