LWN.net Logo

drupal: session hijacking vulnerability

Package(s):drupal CVE #(s):CVE-2008-3661
Created:October 16, 2008 Updated:May 4, 2009
Description: Drupal has a session hijacking vulnerability. From the Red Hat bug report:

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Alerts:
Fedora FEDORA-2008-9213 2008-10-30
Fedora FEDORA-2008-9170 2008-10-24
Fedora FEDORA-2008-8852 2008-10-16
Fedora FEDORA-2008-8905 2008-10-16

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds