CVE-2017-11667: Openproject

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.

Affected products

  • Openproject Openproject: up to and including 6.1.5; version 7.0.0 only; version 7.0.1 only; version 7.0.2 only

Published 2017-07-26. Last modified 2026-06-17.