The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-08-27T09:52:16
Updated: 2024-08-04T00:33:51.312Z
Reserved: 2021-06-23T00:00:00
Link: CVE-2021-35342
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-08-27T10:15:07.793
Modified: 2021-09-01T17:49:19.437
Link: CVE-2021-35342
Redhat
No data.