CVE-2024-29070 Information
Jul 24, 2024
cve
Description
On versions before 2.1.4 session is not invalidated after logout. When the user logged in successfully the Backend service returns \Authorization\ as the front-end authentication credential. \Authorization\ can still initiate requests and access data even after logout.
Mitigation:
all users should upgrade to 2.1.4
Reference
https://lists.apache.org/thread/zslblrz1l0n9t67mqdv42yv75ncfn9zl
Share on: