CVE-2018-20238

CWE-3843 documents3 sources
Severity
8.1HIGH
EPSS
0.2%
top 57.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 14

Description

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5atlassian/crowdunspecified3.2.7+2
NVDatlassian/crowd3.3.03.3.4+1

🔴Vulnerability Details

2
GHSA
GHSA-jj3c-2ggq-fxgg: Various rest resources in Atlassian Crowd before version 32022-05-14
CVEList
CVE-2018-20238: Various rest resources in Atlassian Crowd before version 32019-02-13
CVE-2018-20238 (HIGH CVSS 8.1) | Various rest resources in Atlassian | cvebase.io