Insufficient Session Expiration in Directus - CVE-2024-34709
Published: May 13, 2024 / Updated: April 23, 2026
Directus
Directus
Description
The vulnerability allows a remote user to reuse a leaked session token to access a session after logout.
The vulnerability exists due to insufficient session expiration in session token validation when processing authenticated requests with a previously captured session cookie. A remote user can replay a captured session token to reuse a session after logout.
User interaction is required, and exploitation depends on obtaining the session cookie value before logout or refresh.