296,172
Total vulnerabilities in the database
A security protection device in Session designed to protect session hijacking was not correctly functioning. This function intended to protect user sessions by detecting changes in the User-Agent header, but modifications to this header were not correctly invalidating the user session.
Software | From | Fixed in |
---|---|---|
![]() |
3.5.0-rc1 | 3.5.6 |
![]() |
3.6.0-rc1 | 3.6.3 |