the.bay.news

Security release: hummingbird-auth 2.3.0

Swift Forums
Security release: hummingbird-auth 2.3.0
Users of hummingbird-auth should update to version 2.3.0 now. It includes a fix for the following security advisory Attacker-controlled session id accepted during session creation leads to session fixation When saving sessions SessionMiddleware will check for the SESSION_ID cookie in the request and trust the value provided regardless of whether they are updating an existing session or creating a new session. If an attacker can get a victim's browser to carry an attacker defined SESSION_ID coo...

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.