8000 Session fixation · Issue #364 · snc/SncRedisBundle · GitHub
[go: up one dir, main page]

Skip to content
Session fixation #364
@pascal-hofmann

Description

@pascal-hofmann

The session handler does not check if a session id is valid. It just silently creates a session for non-existent ids. This allows for session fixation attacks.

See also https://www.owasp.org/index.php/Session_fixation and http://php.net/manual/en/session.configuration.php#ini.session.use-strict-mode

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0