Cookies set via HTTP requests may be used to bypass HTTPS and reveal private information

Discussion in 'other security issues & news' started by ronjor, Sep 24, 2015.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,211
    Location:
    Texas
    http://www.kb.cert.org/vuls/id/804060
     
  2. Amanda

    Amanda Registered Member

    Joined:
    Aug 8, 2013
    Posts:
    2,115
    Location:
    Brasil
    I wonder why nobody fixed this, even though they were notified several months ago.

    I'm not sure I understoo the issue correctly, but if I block all cookies by default and only allow certain cookies to be stored (such as this website), I'm safe form this vulnerability?
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,211
    Location:
    Texas
    https://thestack.com/security/2015/...e-websites-vulnerable-in-all-modern-browsers/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.