CVE-2024-23586: An insufficient session timeout vulnerability affects HCL Nomad server on Domino
HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23586?
CVE-2024-23586 has been classified with a moderate severity level due to the potential for unauthorized access to session data.
How do I fix CVE-2024-23586?
To mitigate CVE-2024-23586, ensure that your HCL Nomad software is updated to version 1.0.13 or later, where this vulnerability is addressed.
Who is affected by CVE-2024-23586?
CVE-2024-23586 affects users of HCL Nomad versions prior to 1.0.13 who may be vulnerable to session hijacking.
What type of vulnerability is CVE-2024-23586?
CVE-2024-23586 is an insufficient session expiration vulnerability allowing potential unauthorized access to session information.
Can attackers exploit CVE-2024-23586 remotely?
Yes, CVE-2024-23586 can be exploited by unauthenticated attackers remotely under specific circumstances.