Skip navigation

STANFORD UNIVERSITY

INFORMATION TECHNOLOGY SERVICES

Stanford WebAuth Security Advisories

2009-09-10

WebAuth 3.5.5, 3.6.0, and 3.6.1 have a security vulnerability in the WebLogin server that can, in rare situations, expose the user's password in the URL and from there to the browser history and to WebAuth-protected web sites. All WebLogin servers should be upgraded to WebAuth 3.6.2. See the full advisory for more information.

Last modified Thursday, 10-Sep-2009 02:41:20 PM

Stanford University Home Page