Headline
GHSA-c7q8-m4xw-c674: Hybridsessions does not expire session id on logout
When using the hybridsessions module is used without the session-manager module installed and sessions IDs are saved to disk, unexpired SessionIDs of logged out users can still be used to make authenticated requests.
Package
composer silverstripe/hybridsessions (Composer)
Affected versions
>= 1.0.0, < 2.4.1
>= 2.5.0, < 2.5.1
Patched versions
2.4.1
2.5.1