Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability in Flowintel allows authenticated sessions to remain active even after a user changes their password. This means an attacker who previously gained access via a stolen session token could continue to exploit that access until the session naturally expires, despite the password reset. The primary concern is to confirm if Flowintel is in use and if any previously compromised sessions could still be active.
- Stolen access persists after password reset.
- Confirms ongoing access risks if compromised.
- Verify product usage and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker who has already compromised a user's session can maintain access even after the user changes their password. This is because the application does not properly invalidate existing authenticated sessions when a password reset occurs, allowing the attacker's session to continue until it naturally expires. The vulnerability ultimately exposes sensitive data or actions that the compromised session can access.
- Requires an existing valid session.
- Triggered by a user changing their password.
- Risk of continued unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
When Flowintel does not revoke existing authenticated sessions after a user changes their password, an attacker who previously obtained a valid session token could maintain access to the user's account until that session naturally expires. This condition could allow continued unauthorized access to the system.
- Existing authenticated sessions may remain active.
- Prior session tokens could grant continued access.
- Unauthorized access persists until session expiry.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Flowintel's session management, potentially allowing unrevoked access for attackers who have already compromised a session. Application owners or platform teams are likely responsible for managing Flowintel, and their first step should be to identify all active Flowintel instances, determine their reachability and criticality, and locate the accountable owner for each instance to plan remediation.
- Application or platform teams should own this issue.
- Verify Flowintel instance reachability and criticality.
- Plan vendor-coordinated remediation.