Potential session fixation attack #2626
Robin Shen opened 6 months ago

Session should be replaced upon login to prevent session fixation attack

  • Robin Shen changed fields 6 months ago
    Name Previous Value Current Value
    Priority
    Normal
    Major
  • OneDev commented 6 months ago

    State changed as code fixing the issue is committed (afb984e5)

  • OneDev changed state to 'Closed' 6 months ago
    Previous Value Current Value
    Open
    Closed
  • OneDev commented 6 months ago

    State changed as build OD-6864 is successful

  • OneDev changed state to 'Released' 6 months ago
    Previous Value Current Value
    Closed
    Released
  • Robin Shen changed title 6 months ago
    Previous Value Current Value
    Session not replaced upon login
    Potential session fixation attack
1/1
Type
Security Vulnerability
Priority
Major
Assignee
Labels
No labels
Issue Votes (0)
Watchers (3)
Reference
OD-2626
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover