{"id":"CVE-2021-25979","aliases":["GHSA-9j9m-8wjc-ff96"],"url":"https://o3.security/vulnerability/CVE-2021-25979","summary":" Apostrophe CMS Insufficient Session Expiration vulnerability","details":"Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be archived (3.x) or moved to the trash (2.x and earlier) which does disable the existing session.","published":"2021-11-08T15:15:07.743Z","modified":"2026-08-07T15:15:17.932207Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01103,"percentile":0.62743,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"apostrophe","fixedVersion":"3.4.0"}],"fix":{"url":"https://github.com/apostrophecms/apostrophe/commit/c211b211f9f4303a77a307cf41aac9b4ef8d2c7c","label":"apostrophecms/apostrophe@c211b21"},"references":[{"type":"FIX","url":"https://github.com/apostrophecms/apostrophe/commit/c211b211f9f4303a77a307cf41aac9b4ef8d2c7c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:15:17.932207Z"}}