X2Go Bug report logs - #1295
x2goclient/broker mode : don't close on suspended session with --close-disconnect

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Walid MOGHRABI <w.moghrabi@servicemagic.eu>

Date: Wed, 9 May 2018 14:05:02 UTC

Severity: normal

Found in version

Full log

package: x2goclient
priority: bug

In broker/tce mode, when I connect a new session on TCE-CLIENT-1, if I live migrate the running session on TCE-CLIENT-2, the session is detached from client 1 to client 2 correctly (suspended on client 1 and correctly resumed on client 2) but x2goclient doesn't close itself on client 1 once session is detached.
The client stays opened on the sessions profiles list with the currently logged in user instead of closing itself and getting back to the broker login prompt.

This is a major security issue since anyone can then just click on a session profile to connect with the current user credentials. 

Walid Moghrabi

