VOOZH about

URL: https://lwn.net/Articles/304158/

⇱ mantis: insecure cookies [LWN.net]


👁 LWN.net Logo
LWN
.net
News from the source 👁 LWN
| |
Log in / Subscribe / Register

mantis: insecure cookies

Package(s):mantis CVE #(s):CVE-2008-3102
Created:October 21, 2008 Updated:December 2, 2008
Description: From the CVE entry: Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Alerts:
Gentoo 200812-07 mantisbt 2008-12-02
Fedora FEDORA-2008-9015 mantis 2008-10-20
Fedora FEDORA-2008-8925 mantis 2008-10-20