From 068688063eb660d35ee0dca8d3ceb53d2f243bbe Mon Sep 17 00:00:00 2001 From: NARUKAWA Hiroki Date: Fri, 20 Dec 2013 03:38:51 +0900 Subject: [PATCH] Security Update: session fixation Previous version is vulnerable to session fixation attack in some situations, guessing non-apache-module-php5 environment. Regeneration of session id should be done here. --- lib/private/user/session.php | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/private/user/session.php b/lib/private/user/session.php index c2885d00413..67cfdf2624e 100644 --- a/lib/private/user/session.php +++ b/lib/private/user/session.php @@ -157,6 +157,7 @@ class Session implements Emitter, \OCP\IUserSession { if($user !== false) { if (!is_null($user)) { if ($user->isEnabled()) { + session_regenerate_id(true); $this->setUser($user); $this->setLoginname($uid); $this->manager->emit('\OC\User', 'postLogin', array($user, $password));