{"id":"CVE-2021-25979","details":"Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.","aliases":["GHSA-9j9m-8wjc-ff96"],"modified":"2026-08-07T15:15:17.932207Z","published":"2021-11-08T15:15:07.743Z","references":[{"type":"FIX","url":"https://github.com/apostrophecms/apostrophe/commit/c211b211f9f4303a77a307cf41aac9b4ef8d2c7c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apostrophecms/apostrophe","events":[{"introduced":"0ae930a861a077f52c7995d4425b3fecee3775d2"},{"fixed":"71221f7463372c0e2c7c7638d9fc6f6b85d38239"},{"fixed":"c211b211f9f4303a77a307cf41aac9b4ef8d2c7c"}],"database_specific":{"cpe":"cpe:2.3:a:apostrophecms:apostrophecms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.63.0"},{"fixed":"3.3.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.3.0","3.2.0","3.1.2","3.1.0","3.0.1","3.0.0","3.0.0-beta.3","3.0.0-beta.2","3.0.0-beta.1.1","3.0.0-beta.1","3.0.0-alpha.7","3.0.0-alpha.6.1","3.0.0-alpha.5","3.0.0-alpha.4.2","3.0.0-alpha.4","3.0.0-alpha.3","3.0.0-alpha.2","3.0.0-alpha.1","2.67.0","2.66.0","2.65.0","2.64.1","2.64.0","2.63.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25979.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}