Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
wire-webapp Has Insufficient Session Invalidation after User Logout
Vulnerability Description
wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user is logged in as a temporary user by selecting "This is a public computer" during login or the user selects "Delete all your personal information and conversations on this device" upon logout. The underlying issue has been fixed with wire-webapp version 2025-05-20-production.0. As a workaround, this behavior can be prevented by either deleting all information upon logout as well as logging in as a temporary client.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
wire-webapp 安全漏洞
Vulnerability Description
wire-webapp是Wire Swiss开源的一个应用程序。 wire-webapp 2025-05-20-production.0之前版本存在安全漏洞,该漏洞源于会话未正确失效,可能导致自动重新登录。
CVSS Information
N/A
Vulnerability Type
N/A