Bug 1216508 - VUL-1: HAWK: insecure cookie configuration
Summary: VUL-1: HAWK: insecure cookie configuration
Status: RESOLVED FIXED
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Aleksei Burlakov
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 1215795
  Show dependency treegraph
 
Reported: 2023-10-23 15:28 UTC by Paolo Perego
Modified: 2024-01-31 12:30 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paolo Perego 2023-10-23 15:28:53 UTC
The hawk session has 3 different cookies:
* hawk
* hawk_remember_me_id
* hawk_remember_me_key

None of those cookies are configured to have HTTPOnly and Secure flag.

CVSS is 3.1 (https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N&version=3.1)
Comment 7 Aleksei Burlakov 2023-11-21 11:36:55 UTC
I did this change in the https://github.com/ClusterLabs/hawk/pull/273
Comment 8 Paolo Perego 2023-11-21 13:39:17 UTC
(In reply to Aleksei Burlakov from comment #7)
> I did this change in the https://github.com/ClusterLabs/hawk/pull/273

Super Aleksei, thank you so much. Closing the ticket since the fix is upstream
Comment 11 Maintenance Automation 2024-01-10 12:30:02 UTC
SUSE-SU-2024:0076-1: An update that has eight security fixes can now be installed.

Category: security (moderate)
Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571
Sources used:
openSUSE Leap 15.4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1
SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Maintenance Automation 2024-01-31 12:30:29 UTC
SUSE-RU-2024:0282-1: An update that has eight fixes can now be installed.

Category: recommended (moderate)
Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571
Sources used:
openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1
SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1
SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1
SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1
SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1
SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.