Bug 713477 - [RFE] RHN Satellite / Spacewalk: Enable HTTPOnly cookies support in Satellite / Spacewalk (CWE-79)
Summary: [RFE] RHN Satellite / Spacewalk: Enable HTTPOnly cookies support in Satellite...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: WebUI
Version: 541
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Michael Mráka
QA Contact: Martin Minar
URL:
Whiteboard: public=20110915,reported=20110522,sou...
: 710620 (view as bug list)
Depends On:
Blocks: 622406 sat541-triage
TreeView+ depends on / blocked
 
Reported: 2011-06-15 14:09 UTC by Jan Lieskovsky
Modified: 2018-11-14 12:28 UTC (History)
12 users (show)

Fixed In Version: spacewalk-config-1.2.2-7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-09-15 17:55:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1299 0 normal SHIPPED_LIVE Moderate: Red Hat Network Satellite server security and enhancement update 2011-09-15 17:54:55 UTC

Description Jan Lieskovsky 2011-06-15 14:09:22 UTC
Implementing support for HTTPOnly cookies (access allowed only for server
and prohibited for client script) in Red Hat Network Satellite / Spacewalk
services could block exploitation of some XSS flaws.

References:
[1] http://www.codinghorror.com/blog/2008/08/protecting-your-cookies-httponly.html
[2] http://stackoverflow.com/questions/528405/which-browsers-do-support-httponly-cookies
[3] https://www.owasp.org/index.php/HttpOnly
[4] http://en.wikipedia.org/wiki/HTTP_cookie#HttpOnly_cookie
[5] http://w2spconf.com/2010/papers/p25.pdf
[6] http://stackoverflow.com/questions/33412/how-do-you-configure-httponly-cookies-in-tomcat-java-webapps

Comment 5 Clifford Perry 2011-06-15 17:50:36 UTC
*** Bug 710620 has been marked as a duplicate of this bug. ***

Comment 23 errata-xmlrpc 2011-09-15 17:55:57 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2011-1299.html

Comment 24 Michael Mráka 2011-09-16 09:19:48 UTC
The issue has been addressed in Spacewalk master by
commit a779c73eab6a65f38a03d8fb27b06cc1f71842fc
    713477 - made session cookies httponly

Fixed package: spacewalk-config-1.6.2-1


Note You need to log in before you can comment on or make changes to this bug.