Vulnerability Description
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chatwoot | Chatwoot | < 2.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/chatwoot/chatwoot/commit/6fdd4a29969be8423f31890b807d27d13627Patch
- https://huntr.com/bounties/1625470476437-chatwoot/chatwootBroken Link
FAQ
What is CVE-2021-3740?
CVE-2021-3740 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowin...
How severe is CVE-2021-3740?
CVE-2021-3740 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3740?
Check the references section above for vendor advisories and patch information. Affected products include: Chatwoot Chatwoot.