angler-fishThe Vulnerability History Project

[1.8.x] Fixed #19324 -- Avoided creating a session record when loading the session.

      The session record is now only created if/when the session is modified. This
prevents a potential DoS via creation of many empty session records.

This is a security fix; disclosure to follow shortly.
    
commit 66d12d1ababa8f062857ee5eb43276493720bf16
+2 -4
+2 -2
+2 -3
+2 -3
-21
-21
-21
-20
expand_less