0
Not a bug

Logged out Agent can still establish a Session

Stuart 4 years ago updated by anonymous 4 years ago 6

This is a security concern.


An agent gets timed out after X minutes of inactivity in the web panel. However, even after the agent has been timed out, someone can still right click on a computer and choose Join. This will establish the session to the remote guest even though the agent doesn't have a valid session.


Steps to Reproduce:

1) Have the agent log in and click on Access so that they have a list of computers available to them.

2) In a new tab on the same browser, have the agent click their name then log out.

3) Verify in that tab that the agent cannot browse the web portal.

4) Go back to the original tab and right click a computer and select "Join".

5) Even though the agent is no longer logged in, the session still joins.

ConnectWise Control Version:
Server Affected:
Host Client Affected:
Guest Client Affected:

Thank you for submitting this information. I was able to reproduce the behavior you describe in our test environment and have registered the issue with development.

Started
Planned
Started
Fixed
Not a bug
Commenting disabled