silverstripe/framework's User-Agent header not correctly invalidating user session
High severity
GitHub Reviewed
Published
May 27, 2024
to the GitHub Advisory Database
Package
Affected versions
>= 3.5.0-rc1, < 3.5.6
>= 3.6.0-rc1, < 3.6.3
Patched versions
3.5.6
3.6.3
Description
Published to the GitHub Advisory Database
May 27, 2024
Reviewed
May 27, 2024
A security protection device in Session designed to protect session hijacking was not correctly functioning. This function intended to protect user sessions by detecting changes in the User-Agent header, but modifications to this header were not correctly invalidating the user session.
References