Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The data and session sections are not filtered, and can leak sensitive information #364

Open
trammel opened this issue Aug 29, 2016 · 0 comments

Comments

@trammel
Copy link

trammel commented Aug 29, 2016

In the default _data and _session templates serialize the @DaTa and @request.session information, but they aren't filtered. So sensitive information like the session_id and any other information stored there are exposed via whatever notification mechanism is used.

#363 submitted as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant