CVE-2025-51306 Information

Description

In Gatling Enterprise versions below 1.25.0 a user logging-out can still use his session token to continue using the application without expiration due to incorrect session management.

Reference

https://gatling.io/products https://github.com/Flo354/vulnerabilities/blob/main/gatling-enterprise/CVE-2025-51306-broken-logout.md https://github.com/Flo354/vulnerabilities/blob/main/gatling-enterprise/CVE-2025-51306-change-permissions-not-reflected.md https://github.com/Flo354/vulnerabilities/tree/main/gatling-enterprise

CNNVD-202508-598 (Published: 2025-08-06)

Share on: