Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2264

CVE-2023-1973 SessionImpl objects + location strings are created and not cleaned up on authentication failures

XMLWordPrintable

    FormAuthenticationMechanism creates SessionImpl objects for every attempt to login, even unsuccessful ones. Those sessions have strings with the location attached and are not being cleaned up properly. 

          ropalka Richard Opalka
          flaviarnn Flavia Rainone
          Bartosz Baranowski, Carlo de Wolf, Chao Wang, Chess Hazlett, Flavia Rainone, Jason Lee, Lin Gao, Masafumi Miura, Richard Opalka, Stefano Maestri, Stuart Douglas, Tom Jenkinson
          Votes:
          0 Vote for this issue
          Watchers:
          6 Start watching this issue

            Created:
            Updated:
            Resolved: