A user's privileges may change during a session. If this information is also stored in session data, it will not reflect the changes. Consider forcing re-authentication.
See Authentication AT 9 for other re-authentication requirements.
Matt can abuse long sessions because the application does not require periodic re-authentication to check if privileges have changed
Owasp ASVS (4.0): 3.6.1 ,3.3.2
Capec: 21
Owasp SCP: 96
Owasp Appsensor:
Safecode: 28
ASVS V3.6 - Re-authentication from a Federation or Assertion
ASVS V3.3 - Session Logout and Timeout Requirements
Password Guessing/Brute Force Attacks
Session Hijacking (Man-in-the-Middle)
Loading comments 0%