We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-48061

wire-webapp Has Insufficient Session Invalidation after User Logout



Description

wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user is logged in as a temporary user by selecting "This is a public computer" during login or the user selects "Delete all your personal information and conversations on this device" upon logout. The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0. As a workaround, this behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client.

Reserved 2025-05-15 | Published 2025-05-22 | Updated 2025-05-22 | Assigner GitHub_M


MEDIUM: 5.6CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-613: Insufficient Session Expiration

Product status

< 2025-05-20-production.0
affected

References

github.com/...webapp/security/advisories/GHSA-7r6m-qjwm-w44q

cve.org (CVE-2025-48061)

nvd.nist.gov (CVE-2025-48061)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-48061

Support options

Helpdesk Chat, Email, Knowledgebase