Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[UNDERTOW-2264] CVE-2023-1973 Force session timeout to 2 minutes when… #1581

Merged
merged 1 commit into from Apr 19, 2024

Conversation

fl4via
Copy link
Member

@fl4via fl4via commented Apr 18, 2024

… session was created during the authentication phase. Once authentication is complete restore original (configured) session timeout.

Jira: https://issues.redhat.com/browse/UNDERTOW-2264
2.2.x PR: #1583

… session was created during the authentication phase. Once authentication is complete restore original (configured) session timeout.

Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via fl4via added bug fix Contains bug fix(es) next release This PR will be merged before next release or has already been merged (for payload double check) waiting CI check Ready to be merged but waiting for CI check labels Apr 18, 2024
@fl4via fl4via merged commit 485fd79 into undertow-io:master Apr 19, 2024
34 checks passed
@fl4via fl4via removed the waiting CI check Ready to be merged but waiting for CI check label Apr 19, 2024
@fl4via fl4via deleted the UNDERTOW-2264 branch April 19, 2024 03:04
@fl4via fl4via removed the next release This PR will be merged before next release or has already been merged (for payload double check) label Apr 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug fix Contains bug fix(es)
Projects
None yet
2 participants