SB2025112871 - Insufficient session expiration in Memos
Published: November 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient session expiration (CVE-ID: CVE-2024-21635)
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to the application does not invalidate tokens after password change. The access token remains valid and allows an attacker to gain access to the victim's account even after the victim changes their password.
Remediation
Install update from vendor's website.