Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.
The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.
CVE ID: CVE-2024-55931
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.3
Vendor: Xerox
Product: Xerox Workplace Suite
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.72% (scored less or equal to compared to others)
EPSS Date: 2025-02-25 (when was this score calculated)