Home
MEDIUM: 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:LDefault status
unaffected
Any version before 1.12.0
affected
Description
An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version before 1.12.0
References
selinc.com/products/software/latest-software-versions/