RubySec

Providing security resources for the Ruby community

CVE-2021-25970 (camaleon_cms): Camaleon CMS Insufficient Session Expiration vulnerability

ADVISORIES

GEM

camaleon_cms

SEVERITY

CVSS v3.x: 8.8 (High)

UNAFFECTED VERSIONS

  • < 0.1.7

PATCHED VERSIONS

  • >= 2.6.0.1

DESCRIPTION

Camaleon CMS 0.1.7 through 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.

RELATED