cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2049
Views
0
Helpful
6
Replies

WebEx Windows Desktop App - Logout not possible - Security Bug

IFM Admin
Level 1
Level 1

Hello,

i do not find a Way to Logout from the Windows Desktop App, after logout i am still the user i was logged in before.

 

Her the steps i do:

 

  1. A user with a windows pc without webex installed follow a host url like this example:
    https://example.webex.com/example/p.php?AT=LI&WID=usermail&TK=token&MU=https%3A%2F%2Fexample.webex.com%2Fexample%2Fm.php%3FAT%3DHM%26MK%3D1638534520%26Rnd%3D0.5939363143235705
  2. User download the client and is auto logged in. That works fine.
  3. After the Meeting the user logout from the Website and he logout from the Windows Client
  4. To avoid caching issues he restart also the pc
  5. It seems he is logged out every where.
  6. Now he starts a attendee join url like this example:
    https://example.webex.com/example/j.php?MTID=mef7b6a4cad6a01cbac546f4a5ce64730
  7. Now he is again automatically logged in the the meeting as the previous meeting host, without any manually login

This is a big security issue, how is it possible to logout completely from the Desktop Client???

 

If the user choose the Webbased Client he is a Guest, thats fine.

Even revoke the user did not help. 

https://help.webex.com/en-us/nigu6hc/Revoke-a-User-s-Access-to-Cisco-Webex

 

Any idea?

 

BR

6 Replies 6

Fritz_H
VIP Alumni
VIP Alumni

@IFM Admin 
I can not confirm this issue on my system. (Windows 8.1 pro + Webex Meetings Client Version 41.5.5.12 and 41.5.6.9)
As soon as I select "sign out" the application closes and (after 1 or 2 seconds) the log-on screen of the Webex-Meetings-Client is shown.

Is there any password-management-Software installed that may interfere with the logon-process of the Webex-Meetings-Client?
If the Webex-Client is invoked by a Webpage/Browser: perhaps this Webbrowser did some credential-caching?

No there is no password management software installed.

I use also Version 41.5.6.9.

 

If i logged out and check the website and Software it seems i logged out.

 

Only if i start a meeting via a join url iam logged in automatically with the previous used user in the host url.

Did you really also used a host url with a TK token?

 

@IFM Admin 
I tested the Client-behavior only.
I am still considering something like a browser-related issue since such an obvious bug would have been noticed by other users too by now.

On the other hand: the average webex-user does not use different Webex-"Identities" on the same Windows-Account...
hmm.


@Fritz_H wrote:

On the other hand: the average webex-user does not use different Webex-"Identities" on the same Windows-Account...
hmm.


I called the hotline and open a ticket for that issue and the support confirmed my describes behavior. So it is really a known issue.

 


@Fritz_H wrote:

On the other hand: the average webex-user does not use different Webex-"Identities" on the same Windows-Account...
hmm.


That is correct but nothing of the kind, it should be fixed.

What did you have to do to reslve this?  I'm having the same problem!

Many thanks

@IFM Admin 

Thanks for your message - good news that Cisco-Support was helpful again.



That is correct but nothing of the kind, it should be fixed.


True.
I just wanted to explain what I think could be the reason for lots of views but no replies to your posting.