CVE-2023-37504

CVE-2023-37504

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.

Source: CVE-2023-37504

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다