CVE-2017-11667: High severity openproject vulnerability
Published Jul 26, 2017
·Updated
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
Affected Software
4 affected components
OpenProject OpenProject<=6.1.5
OpenProject OpenProject=7.0.0
OpenProject OpenProject=7.0.1
OpenProject OpenProject=7.0.2
Remediation
Event History
Jul 26, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11667?
CVE-2017-11667 is classified with a medium severity score due to its potential for exploitation through session hijacking.
2
How do I fix CVE-2017-11667?
To fix CVE-2017-11667, upgrade OpenProject to version 6.1.6 or 7.0.3 or later.
3
What versions of OpenProject are affected by CVE-2017-11667?
CVE-2017-11667 affects OpenProject versions before 6.1.6 and any 7.x versions before 7.0.3.
4
Can CVE-2017-11667 lead to unauthorized access?
Yes, CVE-2017-11667 allows remote attackers to perform APIv3 requests indefinitely if they hijack a valid session.
5
Is there a workaround for CVE-2017-11667?
There is no official workaround for CVE-2017-11667; updating to a patched version is recommended.