Jwttoken in Cosmos server never expires after password changed and logging out
CVE-2023-49091

9.8CRITICAL

Key Information:

Vendor

Azukaar

Vendor
CVE Published:
29 November 2023

What is CVE-2023-49091?

Cosmos-Server is a self-hosted application gateway that enables users to manage their home servers securely. However, it contains a flaw related to session management, where the authorization token used for user login persists after logout. This allows attackers to exploit valid tokens to gain unauthorized access to the system, potentially leading to sensitive data exposure or further attacks. To mitigate this risk, users are advised to upgrade to version 0.13.0 where this issue has been resolved.

Affected Version(s)

Cosmos-Server < 0.13.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-49091 : Jwttoken in Cosmos server never expires after password changed and logging out