View Issue Details

IDProjectCategoryView StatusLast Update
000935110000-002: SecuritySpecpublic2025-07-08 16:32
ReporterRandy Armstrong Assigned ToPaul Hunkar  
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version1.05.03 
Target Version1.05.04 RC1Fixed in Version1.05.06 RC1 
Summary0009351: Race conditions for user contexts after the handover of a session to a new user.
Description

Better mitigations:

create a new session for the new credentials, do the higher privilege operation and close the sessions;
do not process new requests until activate session completes; any existing requests finish with the current credentials.
TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Paul Hunkar

2025-06-16 16:27

developer   ~0023012

Added text to explain issues a developer has to deal with when ActiveSession User context changes.

Jim Luth

2025-07-08 16:32

administrator   ~0023096

Agreed to changes edited in Web Meeting.

Issue History

Date Modified Username Field Change
2024-01-11 00:08 Randy Armstrong New Issue
2024-01-11 00:08 Randy Armstrong Status new => assigned
2024-01-11 00:08 Randy Armstrong Assigned To => Paul Hunkar
2025-06-16 16:27 Paul Hunkar Status assigned => resolved
2025-06-16 16:27 Paul Hunkar Resolution open => fixed
2025-06-16 16:27 Paul Hunkar Fixed in Version => 1.05.06 RC1
2025-06-16 16:27 Paul Hunkar Note Added: 0023012
2025-07-08 16:32 Jim Luth Status resolved => closed
2025-07-08 16:32 Jim Luth Note Added: 0023096