CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable.
CVE
CVE-2018-20238
Severity
HIGH
CVSS
8.1
EPSS
1.51%
Original NVD Description
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
Related CVEs
Other vulnerabilities affecting the same vendor(s)