title: Existing sessions are not correctly invalidated when a user changes their password
link: https://contao.org/en/news/security-vulnerability-cve-2019-10641.html
cve: CVE-2019-10641
branches:
4.x:
time: 2019-04-09 10:44:00
versions: ['>=4.0.0', '<4.4.37']
4.5.x:
time: null
versions: ['>=4.5.0', '<4.6.0']
4.6.x:
time: null
versions: ['>=4.6.0', '<4.7.0']
4.7.x:
time: 2019-04-09 12:21:00
versions: ['>=4.7.0', '<4.7.3']
reference: composer://contao/core-bundle
|