← Back to CVEs
CVE-2021-25981
CRITICAL9.8
Description
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/3/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
talkyard:talkyard
Weaknesses (CWE)
CWE-613CWE-613
References
https://github.com/debiki/talkyard/commit/b0310df019887f3464895529c773bc7d85ddcf34(vulnerabilitylab@mend.io)
https://github.com/debiki/talkyard/commit/b0712915d8a22a20b09a129924e8a29c25ae5761(vulnerabilitylab@mend.io)
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25981(vulnerabilitylab@mend.io)
https://github.com/debiki/talkyard/commit/b0310df019887f3464895529c773bc7d85ddcf34(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/debiki/talkyard/commit/b0712915d8a22a20b09a129924e8a29c25ae5761(af854a3a-2127-422b-91ae-364da2661108)
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25981(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.