-
Notifications
You must be signed in to change notification settings - Fork 15
Open
Description
a la https://gist.github.com/mattetti/7624413
tl;dr: encrypted_cookie currently serializes via marshall. This means that anyone who discovers the session secret probably has remote code execution on the application. Which is pretty bad, obviously.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels