ArangoDB - Insufficient Session Expiration after Password Change
Vulnerability Description
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25940
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- WhiteSource Vulnerability Research Team (WVR)
References
Affected Vendor
arangodb
View all reports →