CVE-2024-21492: All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session...

4.8 CVSS

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.

Classification

CVE ID: CVE-2024-21492

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

Affected Products

Vendor: n/a

Product: github.com/greenpau/caddy-security

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGREENPAUCADDYSECURITY-5920787
https://blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddy/
https://github.com/greenpau/caddy-security/issues/272

Timeline