Security Patch Available for JRun 4.0 Token Collision

 
Jul 20, 2005

Under high load, JRun may generate two sessions with the same authentication token. This cannot be controlled by an attacker and it occurs very rarely, but it may cause two authenticated users to share information from a single user session.

Security Patch Available for JRun 4.0 Token Collision (Macromedia Security Bulletin MPSB0505, July 15, 2005)

Add a Comment
(If you subscribe, any new posts to this thread will be sent to your email address.)
  
Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting