{"id":"GHSA-9j9m-8wjc-ff96","summary":" Apostrophe CMS Insufficient Session Expiration vulnerability","details":"Apostrophe CMS versions between 2.63.0 to 3.3.1 affected by an insufficient session expiration vulnerability, which allows unauthenticated remote attackers to hijack recently logged-in users' sessions. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.","aliases":["CVE-2021-25979"],"modified":"2023-11-08T04:05:19.736635Z","published":"2021-11-10T17:02:44Z","database_specific":{"cwe_ids":["CWE-613"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-11-09T21:01:19Z","nvd_published_at":"2021-11-08T15:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25979"},{"type":"WEB","url":"https://github.com/apostrophecms/apostrophe/commit/c211b211f9f4303a77a307cf41aac9b4ef8d2c7c"},{"type":"PACKAGE","url":"https://github.com/apostrophecms/apostrophe"}],"affected":[{"package":{"name":"apostrophe","ecosystem":"npm","purl":"pkg:npm/apostrophe"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.63.0"},{"fixed":"3.4.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-9j9m-8wjc-ff96/GHSA-9j9m-8wjc-ff96.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}