CVE-2023-37504
Last modified
CVE-2023-37504 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Hcl Compass | >= 2.0.0, <= 2.0.3 |
| Hcltech | Hcl Compass | >= 2.2.0, < 2.2.3 |
| Hcltech | Hcl Compass | 2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37504?
How severe is CVE-2023-37504?
How do I fix CVE-2023-37504?
Are you affected by CVE-2023-37504?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
