GitHub has fixed a vulnerability that could lead to user session hijacking.

GitHub announced the reset of all authenticated sessions to GitHub.com, requiring users to log in again due to a security issue. It is noted that the problem occurs very rarely and affects only a small number of sessions, but potentially poses a significant risk as it allows one authenticated user to access another user's session.

The vulnerability is caused by a race condition in backend request processing, leading to the routing of a user's session to another user's browser, which allows full access to the foreign session cookie. It is estimated that the incorrect redirection affected about 0.001% of all authenticated sessions on GitHub.com. It is claimed that such redirection happened under accidental circumstances that could not be deliberately triggered by an attacker. The problematic changes were made on February 8 and were fixed by March 5. On March 8, additional checks were added to provide broader protection against this type of error.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster