VDB
Sign up
—

DRUPAL-CONTRIB-2024-044

Details

This module enables users to remain logged in separately from session timeouts.

The module doesn't sufficiently check a user's disabled status when validating cookies.

This vulnerability is mitigated by the fact that an attacker must have an unexpired cookie from a previous successful login.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/persistent_login
Introduced in: 0Fixed in: 1.8.0

Upgrade drupal/persistent_login to 1.8.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References