← voltar
CVE-2025-68663

Outline has a suspended user authentication bypass via WebSocket connections

CVSS 6.9 MEDIUMEPSS 0.2%CWE-287
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
outline · outline

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →