Impact
Hydro is a next‑generation high-performance online judge platform. From versions 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server‑side session token store, leaving an old sid cookie valid after logout or other renewal flow. An attacker with a stale cookie can replay it over HTTP or HTTPS without knowing the victim’s username or password, and without victim interaction. Successful replay permits the attacker to take over the victim’s account, disclose private data, and modify or delete data available to that account. This vulnerability is a CWE‑613 instance of insufficient session expiration.
Affected Systems
Hydro, version 4.10.4 through 5.0.2 inclusive. The issue affects the session recreation code in packages/hydrooj/src/service/layers/base.ts.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must possess a stale session cookie, which can be obtained through network eavesdropping or replay, and the replay can occur remotely over HTTP or HTTPS with no victim interaction required.
OpenCVE Enrichment
Github GHSA