Cockpit before 2.2.0 vulnerable to Insufficient Session Expiration
Critical severity
GitHub Reviewed
Published
Aug 9, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Aug 8, 2022
Published to the GitHub Advisory Database
Aug 9, 2022
Reviewed
Aug 18, 2022
Last updated
Jan 30, 2023
Cockpit before version 2.2.0 is vulnerable to Insufficient Session Expiration. The application does not validate requests after password changes, allowing a user to change their account details even after an admin changes their password.
References