logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-49091

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-49091

Description:
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid and not expiring after log out. This vulnerability allows an attacker to use the token to gain unauthorized access to the application/system even after the user has logged out. This issue has been patched in version 0.13.0.
Last updated date:
12/08/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/08/2023
Reference url to background

https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-hpvm-x7m8-3c6x

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy