Hi everyone, as far as I can find, every time user logs in with IVY Portal, the session is kept (not renewed). You can check this via JSESSIONID. Thus, it leads to session fixation attack. |
This issue has been fixed in ivy 7.1 and 7.0.4. |
Hi This is a known issue. See https://jira.axonivy.com/jira/browse/XIVY-349 Unfortunately, we cannot fix this issue without breaking RIA applications. However, we plan to drop RIA support in Axon.ivy 8. After that we can fix this issue. Regards Reto Weiss, Axon.ivy Support Thank you for your answer. This means that there is nothing we can do now? 1
Hello @Bao Tran, Just want to update that this issue has been fixed in Ivy 7.0.4 & 7.1 as the US stated. https://developer.axonivy.com/doc/7.1.0/new-and-noteworthy |
Once you sign in you will be able to subscribe for any updates here
By RSS:Markdown Basics
Tags:
Asked: 03.01.2018 at 04:25
Seen: 2,360 times
Last updated: 09.05.2018 at 01:34