We found results for “”
WS-2022-0448
Date: August 23, 2022
Insufficient Session Expiration exists in heroiclabs/nakama through 3.15.0. The Nakama Console session is not invalidated when the user is deleted. An old session can be used by an attacker even after the user has been deleted in a different session. The session can be used until it expires or the attacker logs out.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Insufficient Session Expiration
CWE-613CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |