First published: Wed Aug 14 2024(Updated: )
The BIG-IP Next Central Manager user session refresh token does not expire when a user logs out.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Central Manager | =20.1.0 | 20.2.0 |
F5 BIG-IP Next Central Manager | =20.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39809 has been classified as a vulnerability of medium severity due to the risk of unauthorized access.
To fix CVE-2024-39809, ensure that you update to the latest supported version of F5 BIG-IP Next Central Manager.
CVE-2024-39809 affects F5 BIG-IP Next Central Manager versions 20.1.0 and 20.2.0.
The impact of CVE-2024-39809 is that a user's session may remain active even after they log out, potentially allowing an attacker to exploit this.
Currently, there are no documented workarounds for CVE-2024-39809, and users are advised to upgrade their software instead.