We were notified of a design flaw in the Atlassian suite of products, including Trello, where session cookies do not expire unless a user logs out or after 30 days. Please read their message below:“This of course could make session hijacking easier for an adversary. We want to know what idle timeout settings look like for Trello.References:https://www.darkreading.com/threat-intelligence/security-flaw-in-atlassian-products-affecting-multiple-companieshttps://cloudsek.com/security-flaw-in-atlassian-products-jira-confluencetrello-bitbucket-affecting-multiple-companies/
See https://community.atlassian.com/t5/Trust-Security-articles/Atlassian-response-to-claims-regarding-session-tokens-cookies/ba-p/2217925
It looks like you're new here. Sign in or register to get started.