Session_id without Secure attribute in ikus060/minarca
Reported on
Sep 13th 2022
Description
User's session id with secure attribute is false. This vulnerability makes user's cookies can be sent to the server with an unencrypted request over the HTTP protocol.
Proof of Concept
Open the browser and get access to the minarca website, for this scenario I have used the demo/test website. Check the cookie in browser's dev tool and realize that the cookie with Secure attribute is false.
Impact
This vulnerability makes user's cookies can be sent to the server with an unencrypted request over the HTTP protocol.
References
This vulnerability is valid. Was reported on Rdiffweb project.
Minarca will get fixed, whenever I upgrade Rdiffweb version embedded in Minarca.
Thank you. Yes, If I could edit the affected version It is 4.2.0 for the Minarca.
Sorted the affected version :)
@Patrik - would you like me to assign a CVE for this report?