https://seclists.org/oss-sec/2024/q3/99: CVE-2024-29070: Apache StamPark: session not invalidated after logout
Published Jul 22, 2024
·Updated
Affected Software
1 affected component
Apache Streampark<2.1.4
Frequently Asked Questions
1
What is the severity of CVE-2024-29070?
The severity of CVE-2024-29070 is classified as moderate.
2
What versions are affected by CVE-2024-29070?
CVE-2024-29070 affects Apache StreamPark versions before 2.1.4.
3
How do I fix CVE-2024-29070?
To fix CVE-2024-29070, upgrade Apache StreamPark to version 2.1.4 or later.
4
What is the impact of CVE-2024-29070 on user sessions?
CVE-2024-29070 allows sessions to remain active after a user logs out, which poses a security risk.
5
How does CVE-2024-29070 affect authentication?
CVE-2024-29070 impacts authentication by failing to invalidate the session token upon logout, potentially allowing unauthorized access.