VDB
Sign up
HIGH8.8

GHSA-438x-2p9v-g8h9

Camaleon CMS Insufficient Session Expiration vulnerability

Quick fix

GHSA-438x-2p9v-g8h9 — camaleon_cms: upgrade to the fixed version with the command below.

bundle update camaleon_cms

Details

Camaleon CMS 0.1.7 through 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed. Resolved in commit `77e31bc6cdde7c951fba104aebcd5ebb3f02b030` which is included in the `2.6.0.1` release.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/camaleon_cms
Introduced in: 0.1.7Fixed in: 2.6.0.1
Fixbundle update camaleon_cms

References