Skip to content

Suddenly started using another logged in user's session #19211

Closed
@systems-diplomatic

Description

@systems-diplomatic

Preconditions (*)

  1. Magento 2.2.6 (but we have also seen it on 2.2.4)
  2. FPC enabled or disabled
  3. SID NOT included in URL
  4. At least one item (doesn't matter which one) needs to be in the shopping cart in two user's sessions

Steps to reproduce (*)

  1. Click on link to view cart (not minicart) or go to checkout

Expected result (*)

  1. The user must only see their own details, none from another user.

Actual result (*)

  1. You may see data from another user's session including their cart contents.
  2. From this point the user will see all the information from the other user's session including account information, order history, etc.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Issue: Clear DescriptionGate 2 Passed. Manual verification of the issue description passedIssue: Format is validGate 1 Passed. Automatic verification of issue format passed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions