Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2264

CVE-2023-1973 SessionImpl objects + location strings are created and not cleaned up on authentication failures

XMLWordPrintable

    FormAuthenticationMechanism creates SessionImpl objects for every attempt to login, even unsuccessful ones. Those sessions have strings with the location attached and are not being cleaned up properly. 

            ropalka Richard Opalka
            flaviarnn Flavia Rainone
            Bartosz Baranowski, Carlo de Wolf, Chao Wang, Chess Hazlett, Flavia Rainone, Jason Lee, Lin Gao, Masafumi Miura, Richard Opalka, Stefano Maestri, Stuart Douglas (Inactive), Tom Jenkinson
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated: