Security release: hummingbird-auth 2.3.0
Swift Forums
Security release: hummingbird-auth 2.3.0
Users of hummingbird-auth should update to version 2.3.0 now. It includes a fix for the following security advisory Attacker-controlled session id accepted during session creation leads to session fixation When saving sessions SessionMiddleware will check for the SESSION_ID cookie in the request and trust the value provided regardless of whether they are updating an existing session or creating a new session. If an attacker can get a victim's browser to carry an attacker defined SESSION_ID coo...
0 comments
No comments yet.