angler-fishThe Vulnerability History Project

CVE-2015-5963
aka Empty Crowd Wipeout

Someone can repeatedly make logout requests, which would cause many new empty sessions to be created. This can result in an interruption in service availability by filling up the session store, and it can cause other users' session records to be evicted.



A little bit of it was miscommunication on what logging out really means for a session and its data. A design mistake was made as well by having sessions call self.create() when flushing. The mitigation proposed by the CWE mentions deletion after something is no longer needed. A session should be deleted upon logout, and a new one should not be made.

  • There are no articles here... yet

Timeline

Hover over an event to see its title.
Click on the event to learn more.
Filter by event type with the buttons below.

expand_less