Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4312

Опубликовано: 22 нояб. 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

Отчет

This issue is only a defense-in-depth measure, and we currently have no plans to fix this flaw in Red Hat Enterprise Linux 6. The use of the useHttpOnly setting in Tomcat only prohibits client scripts from accessing cookies when it is correctly implemented in the user's web browser. The use of httpOnly does not guarantee XSS protection; it is only a defense-in-depth measure. Additionally, implementing this as a default setting could have negative impact on existing expected behavior in client scripts. As a result, the Red Hat Security Response Team has determined that this issue is not a security flaw, but a proactive hardening measure and the risk associated with implementing it by default and possibly breaking expected behaviour is greater than any benefits it provides. Users who wish to take advantage of this hardening measure can enable useHttpOnly by adding '' to the default context.xml or a specific web-application context.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tomcat6Affected
Red Hat JBoss Enterprise Web Server 1 for RHEL 4 AStomcat6Affected
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Servertomcat6Affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=658267tomcat6: does not use HTTPOnly for session cookies by default

EPSS

Процентиль: 82%
0.01735
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

nvd
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

debian
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HT ...

github
около 3 лет назад

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

EPSS

Процентиль: 82%
0.01735
Низкий

4.3 Medium

CVSS2