Session Fixation in bytebase/bytebase

Valid

Reported on

Oct 13th 2021


Description

If admin deciding to deactivate a user and the user already logged in the system before then until user remain in the current session he/she can do anything that can do them before.

We have contacted a member of the bytebase team and are waiting to hear back 2 years ago
bytebase/bytebase maintainer validated this vulnerability 2 years ago
amammad has been awarded the disclosure bounty
The fix bounty is now up for grabs
bytebase/bytebase maintainer marked this as fixed with commit b237a4 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation