Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4312

Опубликовано: 22 нояб. 2010
Источник: redhat
CVSS2: 4.3

Описание

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

Отчет

This issue is only a defense-in-depth measure, and we currently have no plans to fix this flaw in Red Hat Enterprise Linux 6. The use of the useHttpOnly setting in Tomcat only prohibits client scripts from accessing cookies when it is correctly implemented in the user's web browser. The use of httpOnly does not guarantee XSS protection; it is only a defense-in-depth measure. Additionally, implementing this as a default setting could have negative impact on existing expected behavior in client scripts. As a result, the Red Hat Security Response Team has determined that this issue is not a security flaw, but a proactive hardening measure and the risk associated with implementing it by default and possibly breaking expected behaviour is greater than any benefits it provides. Users who wish to take advantage of this hardening measure can enable useHttpOnly by adding '' to the default context.xml or a specific web-application context.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tomcat6Affected
Red Hat JBoss Enterprise Web Server 1 for RHEL 4 AStomcat6Affected
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Servertomcat6Affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=658267tomcat6: does not use HTTPOnly for session cookies by default

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

nvd
почти 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

debian
почти 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HT ...

github
больше 3 лет назад

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

4.3 Medium

CVSS2