Description
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 7.3.2024.0409 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47111 | The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:25:03.252Z
Reserved: 2024-06-14T06:53:30.790Z
Link: CVE-2024-5995
Updated: 2024-07-15T20:22:23.478Z
Status : Deferred
Published: 2024-06-14T08:15:43.097
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5995
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD