CVE-2024-55931 – Xerox Workplace Suite Session Token Exposure

The following table lists the changes that have been made to the
CVE-2024-55931 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 10b61619-3869-496c-8a1e-f291b0e71e3f

    Jan. 27, 2025

    Action Type Old Value New Value
    Added Description Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user’s session is compromised. 

    The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
    Added CWE CWE-922
    Added Reference https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf
Share the Post:

Related Posts