OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid in server storage until expiry (default ≈ 1 year). An attacker with a previously stolen or captured session cookie can continue authenticating after logout, resulting in a post-logout authentication bypass. This is a session management flaw that violates expected logout semantics. This issue has been patched in version 3000.11.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gq2m-77hf-vwgh OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 06 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Description OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid in server storage until expiry (default ≈ 1 year). An attacker with a previously stolen or captured session cookie can continue authenticating after logout, resulting in a post-logout authentication bypass. This is a session management flaw that violates expected logout semantics. This issue has been patched in version 3000.11.1.
Title OliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Session
Weaknesses CWE-384
CWE-613
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-06T21:01:37.027Z

Reserved: 2026-03-04T17:23:59.797Z

Link: CVE-2026-30224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T21:16:16.280

Modified: 2026-03-06T21:16:16.280

Link: CVE-2026-30224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses