{"id":"CVE-2021-3311","aliases":["GHSA-7ggw-h8pp-r95r"],"url":"https://o3.security/vulnerability/CVE-2021-3311","summary":"October CMS Session ID not invalidated after logout","details":"An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admittedly, is only relevant if an old session ID is known to an attacker.","published":"2021-02-05T14:15:19.153Z","modified":"2026-09-14T08:12:54.387929Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"october/rain","fixedVersion":"1.0.472"},{"ecosystem":"Packagist","name":"october/rain","fixedVersion":"1.1.2"}],"fix":{"url":"https://github.com/octobercms/library/commit/642f597489e6f644d4bd9a0c267e864cabead024","label":"octobercms/library@642f597"},"references":[{"type":"ADVISORY","url":"https://octobercms.com/forum/chan/announcements"},{"type":"FIX","url":"https://github.com/octobercms/library/commit/642f597489e6f644d4bd9a0c267e864cabead024"},{"type":"EVIDENCE","url":"https://anisiosantos.me/october-cms-token-reactivation"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T08:12:54.387929Z"}}