github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-006-1.yaml GHSA-4QX8-J9VH-2628
silverstripe/framework's User-Agent header not correctly invalidating user session
Description
A security protection device in Session designed to protect session hijacking was not correctly functioning. This function intended to protect user sessions by detecting changes in the User-Agent header, but modifications to this header were not correctly invalidating the user session.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 3.5.0-rc1 to < 3.5.6 · Fixed in 3.5.6 | affected |
| 3.6.0-rc1 to < 3.6.3 · Fixed in 3.6.3 | affected |
References
5github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/commit/44de03da0147e6094b02602b7b73d5b1a1306d78 github.com
https://github.com/silverstripe/silverstripe-framework/commit/d47667bb0768841e4b305fa95d5a4e2ba232c4ad silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2017-006