Description
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-1400 | Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:17:34.704Z
Reserved: 2008-03-19T00:00:00.000Z
Link: CVE-2008-1395
No data.
Status : Modified
Published: 2008-03-20T00:44:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-1395
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD