silverstripe/hybridsessions
Cookie/DB session support for SilverStripe
Activity
- Latest release
- 9mo ago
- Total releases
- 42
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Aug 15, 2014
| Version | Released | |
|---|---|---|
4.0.1
patch
| ||
4.0.0
major
| ||
4.0.0-beta1
pre
| ||
4.0.0-alpha1
pre
| ||
3.0.5
patch
| ||
3.0.4
patch
| ||
3.0.3
patch
| ||
2.7.3
patch
| ||
3.0.2
patch
| ||
2.7.2
patch
| ||
3.0.1
patch
| ||
2.7.1
patch
| ||
3.0.0
major
| ||
3.0.0-rc1
pre
| ||
2.7.0
minor
| ||
2.7.0-beta1
pre
| ||
3.0.0-beta3
pre
| ||
3.0.0-beta2
pre
| ||
3.0.0-beta1
pre
| ||
2.6.0
minor
| ||
2.5.2
patch
| ||
2.4.1
patch
| ||
2.5.1
patch
| ||
2.5.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
2.0.0-beta1
pre
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.0.4
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2022-24444
GHSA-c7q8-m4xw-c674
BIT-silverstripe-2022-24444
Jun 29, 2022
Hybridsessions does not expire session id on logout
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.0-rc1
2.0.0
2.0.0-beta1
+ 11 more Show less
2.0.0-beta2
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.3.0-beta1
2.3.0-rc1
2.4.0
2.5.0
Fixed in
2.4.1
2.5.1
References
Updated Feb 21, 2024 · Source: OSV.dev |