Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-3404

Include CSRF protection for login pages

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Low
    • 2.6.5
    • None
    • None

    Description

      The Crowd webapp and OpenID Server should protect their login page against CSRF attacks. This prevents attacks where a user is logged in under another set of credentials without their permission, or cases where a client is tricked into helping with brute force attacks.

      Attachments

        Activity

          People

            ckrieger Caspar Krieger (Inactive)
            jwalton joe
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: