4.3
CVE-2026-0971
- EPSS 0.18%
- Veröffentlicht 21.04.2026 14:14:23
- Zuletzt bearbeitet 23.04.2026 14:00:26
- Quelle df4dee71-de3a-4139-9588-11b62f
- CVE-Watchlists
- Unerledigt
GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortra ≫ Goanywhere Managed File Transfer Version < 7.10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.077 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| df4dee71-de3a-4139-9588-11b62fe6c0ff | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://fortra.com/security/advisories/product-security/fi-2025-013