CVE-2024-21722
published 2024-02-29CVE-2024-21722: The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
PriorityP434medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.51%
39.8th percentile
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla | joomla_! | >= 3.2.0 < 3.10.15 | 3.10.15 |
| joomla | joomla_! | >= 4.0.0 < 4.4.3 | 4.4.3 |
| joomla | joomla_! | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-fips vulnerabilities
osv·2025-12-15·CVSS 5.5
linux-fips vulnerabilities
linux-fips vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- MTD block device drivers;
- Network drivers;
- DesignWare USB3 driver;
- Ceph distributed file system;
- Network file system (NFS) server daemon;
- NILFS2 file system;
- File systems infrastructure;
- Tracing infrastructure;
- Appletalk network protocol;
- IPv6 networking;
- Netfilter;
(CVE-2021-47146, CVE-2021-47269, CVE-2021-47385, CVE-2021-47634,
CVE-2022-49026, CVE-2024-49935, CVE-2024-50067, CVE-2024-50095,
CVE-2024-50179, CVE-2024-53112, CVE-2024-53217, CVE-2025-21715,
CVE-2025-21722, CVE-
GHSA
GHSA-h4pg-prwh-f695: The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified
ghsa_unreviewed·2024-02-29
CVE-2024-21722 [MEDIUM] CWE-613 GHSA-h4pg-prwh-f695: The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
No detection rules found.
No public exploits indexed.
2024-02-29
Published