CVE-2023-37504
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. Â If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
Source: CVE-2023-37504