Merge branch 'hostnamefix' into 'master'
Hostname checking in httpsession Credentials are checked per session and hostname is checked per request. This can be abused to escalate privileges from one event to another by copying JSESSIONID-cookie from hostname to another See merge request !216
Showing
with
13 additions
and
6 deletions
-
Please register or sign in to post a comment