]
Darran Lofthouse updated ELY-1945:
----------------------------------
Security: (was: Security Issue)
Authentication vulnerable to session fixation attacks
-----------------------------------------------------
Key: ELY-1945
URL:
https://issues.redhat.com/browse/ELY-1945
Project: WildFly Elytron
Issue Type: Bug
Reporter: Mark Banierink
Assignee: Darran Lofthouse
Priority: Critical
The session id is not changed upon authentication. This creates a vulnerability to
session fixation attacks.