Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-1375

Session Fixation Issue

XMLWordPrintable

    • Icon: Defect Defect
    • Resolution: Won't Do
    • Icon: Critical Critical
    • Recycle Bin
    • 1.0.0-RC3
    • Security
    • None

      I don't believe that our current security setup allows us to foil Session Fixation attacks.
      http://en.wikipedia.org/wiki/Session_fixation

      I believe spring security 3 does this "out of the box."

      It does seems as spring security 2.0 (which I believe we're using at this time) does support behavior for guarding against session fixation attacks.
      http://static.springsource.org/spring-security/site/docs/2.0.x/reference/ns-config.html#ns-session-fixation

              Unassigned Unassigned
              nhook Nathan Hook
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: