Web Hack List

Other nomination

Ruby on Rails Session Termination Design Flaw

Rails' default CookieStore holds the whole session in the client cookie, so no server-side record exists to delete at logout. Logging out only issues a replacement cookie and the old one stays valid indefinitely, letting anyone holding a captured cookie re-authenticate later. Rails 2.0 to 4.0 are affected and Rails 4's cookie encryption does not fix it; ActiveRecordStore does.

Record

Researcher
G. S. McNamara
Published by
maverickblogging.com

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of G. S. McNamara, first published at the original source. Preserved copies are kept so the citation survives its host.