View Issue Details

IDProjectCategoryView StatusLast Update
0002008XdebugStep Debuggingpublic2021-10-04 09:32
Reporterderick Assigned To 
PriorityurgentSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version3.1dev 
Target Version3.1devFixed in Version3.1.0 
Summary0002008: Using the XDEBUG_SESSION cookie could bypass shared-secret checks
Description

Xdebug 3.1 adds support for multi-value shared secrets. During the implementation of this, a check was inadvertently dropped to match the XDEBUG_SESSION cookie, as set through browser extensions to activate Xdebug's debugger, against this shared secret. This never made it into a release.

TagsNo tags attached.
Operating System
PHP Version8.0.0-8.0.4

Activities