-
Bug
-
Resolution: Done
-
Major
-
8.0 Update 2
-
False
-
None
-
False
-
-
-
-
-
-
Workaround Exists
-
-
-
If a FORM login page happens to use GET instead of the typical POST to send the login credentials to a custom location, then the short session timeout from UNDERTOW-2378 / UNDERTOW-2264 is still seen after login.
- clones
-
UNDERTOW-2409 Adjust properly session timeout also in case when GET requests with custom auth mechanisms are used
- Resolved
- is caused by
-
UNDERTOW-2264 CVE-2023-1973 SessionImpl objects + location strings are created and not cleaned up on authentication failures
- Reopened
- is incorporated by
-
JBEAP-26990 [GSS](7.4.z) UNDERTOW-2409 / UNDERTOW-2378 - Adjust properly session timeout also in case when custom auth mechanisms are used
- Closed