Just like core in #2164025: Improve security of session ID against DB exposure or SQL injection, the persistent login module should hash the sid value before storing it.

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

greggles created an issue. See original summary.

gapple’s picture

Version: 7.x-1.x-dev » 8.x-1.x-dev
Issue tags: +Security improvements

  • gapple committed adb13966 on 8.x-1.x
    Issue #2569165 by gapple: Improve security of session ID against DB...
gapple’s picture

Title: Improve security of session ID against DB exposure or SQL injection » 2569165-hash-db-values
Status: Active » Fixed
gapple’s picture

Title: 2569165-hash-db-values » Improve security of session ID against DB exposure or SQL injection

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.