CVE-2024-21722: [20240201] - Core - Insufficient session expiration in MFA management views
Published Feb 20, 2024
·Updated
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
Affected Software
3 affected components
Joomla Joomla\!>=3.2.0<3.10.15
Joomla Joomla\!>=4.0.0<4.4.3
Joomla Joomla\!>=5.0.0<5.0.3
Event History
Feb 20, 2024
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21722?
The severity of CVE-2024-21722 is rated as critical due to its potential impact on user session security.
2
How do I fix CVE-2024-21722?
To fix CVE-2024-21722, upgrade to Joomla versions 3.10.16, 4.4.4, or 5.0.4 to ensure proper session management after MFA method changes.
3
Which versions of Joomla are affected by CVE-2024-21722?
CVE-2024-21722 affects Joomla versions between 3.2.0 and 3.10.15, 4.0.0 and 4.4.3, as well as 5.0.0 and 5.0.3.
4
What type of vulnerability is CVE-2024-21722?
CVE-2024-21722 is classified as an insufficient session expiration vulnerability related to multi-factor authentication management.
5
Can I mitigate CVE-2024-21722 without patching?
It is not recommended to rely on mitigation without patching, as the security risks associated with CVE-2024-21722 require software updates.