-
Bug
-
Resolution: Done
-
Critical
-
None
-
None
-
None
-
https://gitlab.cee.redhat.com/undertow-io/undertow/-/merge_requests/76, https://gitlab.cee.redhat.com/undertow-io/undertow/-/merge_requests/82, https://gitlab.cee.redhat.com/undertow-io/undertow/-/commit/6ab54a4e07dd93b2e7bbf58d81de3ad50d09742d, https://gitlab.cee.redhat.com/undertow-io/undertow/-/commit/dcb2933a87447aaf2d8151fa08653e1b333cce26, https://github.com/undertow-io/undertow/pull/1581, https://github.com/undertow-io/undertow/pull/1583
FormAuthenticationMechanism creates SessionImpl objects for every attempt to login, even unsuccessful ones. Those sessions have strings with the location attached and are not being cleaned up properly.
- causes
-
JBEAP-26990 [GSS](7.4.z) UNDERTOW-2378 - Adjust properly session timeout also in case when custom auth mechanisms are used
- Open
-
UNDERTOW-2378 Adjust properly session timeout also in case when custom auth mechanisms are used
- Pull Request Sent
-
JBEAP-26991 [GSS](8.0.z) UNDERTOW-2378 - Adjust properly session timeout also in case when custom auth mechanisms are used
- Pull Request Sent
- is incorporated by
-
WFCORE-6794 CVE-2023-1973 Upgrade Undertow to 2.3.13.Final
- Resolved