We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

vulnerability question

How Do I?

openstack99's avatar
openstack99
1 posts
10 years ago
openstack99's avatar openstack99

Hi Guys, I had run a openvas scan of EE web server and found the following results. Trying to figure out if this is ignorable or if it needs to be addressed. If it does i was hoping someone could provide some pointers. Thanks

Summary The host is running a server with SSL and is prone to information disclosure vulnerability.

Vulnerability Detection Result The cookies:

Set-Cookie: PHPSESSID=je7tgj29l7q85uu6pa1ji5gft6; path=/ Set-Cookie: staging__last_visit=1107617839; expires=Wed, 03-Feb-2016 15:37:19 GMT; path=/;↵ domain=.removed.com; httponly Set-Cookie: staging__last_activity=1422977839; expires=Wed, 03-Feb-2016 15:37:19 GMT; path↵ =/; domain=.remomved.com httponly Set-Cookie: staging__tracker=a💯{i:0;s:5:"index";}; path=/; domain=↵ .removed.com; httponly Set-Cookie: staging__csrf_token=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; do↵ main=.removed.com; httponly Set-Cookie: staging__csrf_token=f4fd5204e1ad368b6df5f8314a7977e4de4e9124; expires=Tue, 03-↵ Feb-2015 17:37:19 GMT; path=/; domain=.removed.com; httponly Set-Cookie: staging__stashid=a🔢{s🔢”id”;s:40:”1b6f125f2f3cd89d897↵ c57d7d37309b775279e0e”;s🔢”dt”;i:1422977839;}; path=/; domain=.removed↵ .com; httponly

are missing the secure attribute.

Affected Software/OS Server with SSL.

Workaround: Set the ‘secure’ attribute for any cookies that are sent over an SSL connection.

Vulnerability Insight The flaw is due to SSL cookie is not using ‘secure’ attribute, which allows cookie to be passed to the server by the client over non-secure channels (http) and allows attacker to conduct session hijacking attacks. remote systems.

Impact Level: Application

       
openstack99's avatar
openstack99
1 posts
10 years ago
openstack99's avatar openstack99

Still waiting for replies =D

Bump

       
Jeremy S.'s avatar
Jeremy S.
353 posts
10 years ago
Jeremy S.'s avatar Jeremy S.

Well, this is not an EE issue (and if it was you haven’t provided the version #), but with your underlying server. I believe this is an Apache issue. Make sure you are running Apache 1.8.10 and ensure cookies are set to secure.

That is all assuming you have valid certificates and are running/forcing https.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.