ID |
CVE-2025-22386
|
Sažetak |
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable. |
Reference |
|
CVSS |
Base: | 7.3 |
Impact: | 5.2 |
Exploitability: | 2.1 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
LOW |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
HIGH |
NONE |
|
CVSS vektor |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Zadnje važnije ažuriranje |
06-01-2025 - 16:15 |
Objavljeno |
04-01-2025 - 02:15 |