We were notified of a design flaw in the Atlassian suite of products, including Trello, where session cookies do not expire unless a user logs out or after 30 days. Please read their message below:
“This of course could make session hijacking easier for an adversary. We want to know what idle timeout settings look like for Trello.
References:
https://www.darkreading.com/threat-intelligence/security-flaw-in-atlassian-products-affecting-multiple-companies
https://cloudsek.com/security-flaw-in-atlassian-products-jira-confluencetrello-bitbucket-affecting-multiple-companies/
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.