Description

A security protection device in Session designed to protect session hijacking was not correctly functioning. This function intended to protect user sessions by detecting changes in the User-Agent header, but modifications to this header were not correctly invalidating the user session.

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory3.5.0-rc1 to < 3.5.6 · Fixed in 3.5.6affected
3.6.0-rc1 to < 3.6.3 · Fixed in 3.6.3affected

References

5