In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.
References
Link Resource
https://security.nozominetworks.com/NN-2023:8-01 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Nozomi

Published: 2023-08-09T07:50:56.736Z

Updated: 2024-05-28T12:44:23.640Z

Reserved: 2023-01-24T10:39:24.290Z


Link: CVE-2023-24477

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-08-09T08:15:09.280

Modified: 2024-05-28T13:15:09.593


Link: CVE-2023-24477

JSON object: View

cve-icon Redhat Information

No data.

CWE