Bugzilla – Bug 1216508
VUL-1: HAWK: insecure cookie configuration
Last modified: 2024-01-31 12:30:29 UTC
The hawk session has 3 different cookies: * hawk * hawk_remember_me_id * hawk_remember_me_key None of those cookies are configured to have HTTPOnly and Secure flag. CVSS is 3.1 (https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N&version=3.1)
I did this change in the https://github.com/ClusterLabs/hawk/pull/273
(In reply to Aleksei Burlakov from comment #7) > I did this change in the https://github.com/ClusterLabs/hawk/pull/273 Super Aleksei, thank you so much. Closing the ticket since the fix is upstream
SUSE-SU-2024:0076-1: An update that has eight security fixes can now be installed. Category: security (moderate) Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571 Sources used: openSUSE Leap 15.4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-RU-2024:0282-1: An update that has eight fixes can now be installed. Category: recommended (moderate) Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571 Sources used: openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.