CVE-2017-11667
N/A
N/A
Summary
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.openproject.org/openproject-6-1-6-released-security-fix/
- https://www.openproject.org/openproject-7-0-3-released/
- https://github.com/opf/openproject/commit/0fdd7578909d2ec50abc275fc4962e99566437ee
References
- https://www.openproject.org/openproject-6-1-6-released-security-fix/
- https://www.openproject.org/openproject-7-0-3-released/
- https://github.com/opf/openproject/commit/0fdd7578909d2ec50abc275fc4962e99566437ee
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.