CVE-2023-4190
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-4190 is a session expiration issue affecting the GitHub repository admidio/admidio before version 4.2.11. The vulnerability permits unauthorized access to user accounts if an attacker obtains a valid session cookie. Users are advised to update the repository to the latest version or take measures to secure their session cookies to mitigate this risk. This weakness could lead to serious consequences, including data breaches and unauthorized actions on the affected accounts. The admidio team has released a patch to address the issue, and users are encouraged to install it promptly to protect their repository from potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jetty
- Debian
Affected Vendors
- Debian