Uploaded image for project: 'Cockpit'
  1. Cockpit
  2. COCKPIT-1153

Only allow one direct login to a remote machine in a session

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Major Major
    • cy24q3
    • None
    • Authentication
    • None
    • 5
    • False
    • Hide

      None

      Show
      None
    • False
    • Testable
    • ?
    • ?
    • rhel-cockpit
    • ?

      It's allegedly possible to open a tab with the login page, log in to a remote machine A, then open a second tab which will give the login page again (as it has a different URL due to the nonexisting =nostname), and log into machine B.

      Then requests from machine B get both login cookies for both sessions. If that is really true, then machine B can completely own machine A.

      This needs to be disallowed. Either ws will plainly reject a request with a cookie for a non-matching host (403 page), or redirect it to the existing session.

              mvollmer1@redhat.com Marius Vollmer
              rhn-engineering-mpitt Martin Pitt
              Marius Vollmer
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: