[request-tracker-maintainers] Bug#614575: request-tracker3.8: Back button attacks

Dominic Hargreaves dom at earth.li
Tue Feb 22 11:44:03 UTC 2011


Package: request-tracker3.8
Version: 3.8.8-7
Severity: important
Tags: security

The following appears in the changelog of 3.8.9:

 * Redirect users to their desired pages after login.
    This prevents possible back button attacks after a user logs out.

This may warrant an update in s-p-u.





More information about the pkg-request-tracker-maintainers mailing list