OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
| Software | From | Fixed in |
|---|---|---|
| openproject / openproject | 7.0.1 | 7.0.1.x |
| openproject / openproject | 7.0.2 | 7.0.2.x |
| openproject / openproject | - | 6.1.5.x |
| openproject / openproject | 7.0.0 | 7.0.0.x |