plone.session@3.0a2 vulnerabilities

Session based auth tkt authentication for Zope

  • latest version

    4.0.4

  • latest non vulnerable version

  • first published

    17 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the plone.session package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Insufficient Session Expiration

    plone.session is a package that implements secure session management for Zope sites.

    Affected versions of this package are vulnerable to Insufficient Session Expiration. The default timeout of session was two hours and allowed for potential attack vectors.

    How to fix Insufficient Session Expiration?

    Upgrade plone.session to version 3.6.2 or higher.

    [,3.6.2)