Session key exposure through session list in Django User Sessions
Moderate severity
GitHub Reviewed
Published
Jan 24, 2020
in
jazzband/django-user-sessions
•
Updated Sep 16, 2024
Description
Reviewed
Jan 24, 2020
Published to the GitHub Advisory Database
Jan 24, 2020
Last updated
Sep 16, 2024
Impact
The views provided by django-user-sessions allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be extracted by the attacker and a session takeover could happen.
Patches
Patch is under way.
Workarounds
Remove the session_key from the template.
References
None.
For more information
If you have any questions or comments about this advisory:
References