We are running CAS 3.6 with tomcat 8 and in some instances when 2 users are 
logging in user A is logged in as User B on the client application. So the 
session information for the first user ends up being used.

We noticed that in the tomcat access logs both users shared the same 
Jsessionid. It appears that a unique Jsessionid was not generated for the 
second user when they arrived on the login page.

Has anyone encountered a similar issue? If so any suggestions.


Juan Quintanilla

