Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-24590

Ambari is keeping the Session cookie even after logout

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • None

    Description

      Ambari is keeping the session cookie in the response even after logout from ambari.

      Ambari is vulnerable to session replay attack due to this vulnerability .

      we should remove the 'AMBARISESSIONID' once the user is logged out.

      Please refer to attached screenshot.

      Attachments

        1. AMBARI_SESSION_ID.png
          81 kB
          Akhil Naik

        Activity

          People

            Unassigned Unassigned
            asnaik Akhil Naik
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: