Skip to content
  • Projects
  • Groups
  • Snippets
  • Help

Codecrew / Moya

  • This project
    • Loading...
  • Sign in
Go to a project
  • Project
  • Repository
  • Issues 30
  • Merge Requests 2
  • Wiki
  • Snippets
  • Settings
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Commits
  • Issue Boards
Merged
Merge Request !216 opened Jan 11, 2015 by Tuomas Riihimäki@tuomari

Hostname checking in httpsession

Credentials are checked per session and hostname is checked per request. This can be abused to escalate privileges from one event to another by copying JSESSIONID-cookie from hostname to another

Edited Jan 11, 2015
Request to merge tuomari:hostnamefix into master

Merged

  • The changes were merged into master.
  • The source branch has been removed.
  • Discussion 0
  • Commits 1
  • Changes 1
  • {{ resolvedDiscussionCount }}/{{ discussionCount }} {{ resolvedCountText }} resolved
  • Juho Juopperi @jkj

    mentioned in commit b1c2c9b5

    Jan 11, 2015

    mentioned in commit b1c2c9b5

    Toggle commit list
  • Write
  • Preview
Markdown is supported
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
  • Please register or sign in to post a comment
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View labels
2
2 participants
Reference: codecrew/moya!216