You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "rickboker (Jira)" <ji...@apache.org> on 2022/12/03 10:03:00 UTC

[jira] [Created] (HADOOP-18558) Web UI has no session controller.There is a risk of session hijacking.

rickboker created HADOOP-18558:
----------------------------------

             Summary: Web UI has no session controller.There is a risk of session hijacking.
                 Key: HADOOP-18558
                 URL: https://issues.apache.org/jira/browse/HADOOP-18558
             Project: Hadoop Common
          Issue Type: Improvement
          Components: website
    Affects Versions: 3.3.1
            Reporter: rickboker


Hadoop web ui didn't manage session,Once login the session will not close at all.There is a risk of session hijacking.we should set sessionĀ {color:#0747a6}MaxInactiveInterval.{color}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org