View Issue Details

IDProjectCategoryView StatusLast Update
000935110000-002: SecuritySpecpublic2024-01-11 00:08
ReporterRandy Armstrong Assigned ToPaul Hunkar  
PrioritynormalSeverityminorReproducibilityalways
Status assignedResolutionopen 
Product Version1.05.03 
Target Version1.05.04 RC1 
Summary0009351: Race conditions for user contexts after the handover of a session to a new user.
Description

Better mitigations:

create a new session for the new credentials, do the higher privilege operation and close the sessions;
do not process new requests until activate session completes; any existing requests finish with the current credentials.
TagsNo tags attached.
Commit Version
Fix Due Date

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2024-01-11 00:08 Randy Armstrong New Issue
2024-01-11 00:08 Randy Armstrong Status new => assigned
2024-01-11 00:08 Randy Armstrong Assigned To => Paul Hunkar