The cookie session ID is of insufficient length and can...
Critical severity
Unreviewed
Published
Oct 26, 2023
to the GitHub Advisory Database
•
Updated Nov 16, 2023
Description
Published by the National Vulnerability Database
Oct 26, 2023
Published to the GitHub Advisory Database
Oct 26, 2023
Last updated
Nov 16, 2023
The cookie session ID is of insufficient length and can be exploited by
brute force, which may allow a remote attacker to obtain a valid
session, bypass authentication, and manipulate the transmitter.
References