Web Hack List

Collected research

Ruby on Rails Session Termination Design Flaw

MaverickBlogging | technology & art by G. S. McNamara

Rails' default CookieStore holds the whole session in the client cookie, so no server-side record exists to delete at logout. Logging out only issues a replacement cookie and the old one stays valid indefinitely, letting anyone holding a captured cookie re-authenticate later. Rails 2.0 to 4.0 are affected and Rails 4's cookie encryption does not fix it; ActiveRecordStore does.

Record

Document
MaverickBlogging | technology & art by G. S. McNamara
Researcher
G. S. McNamara
Published by
maverickblogging.com
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of G. S. McNamara, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .