Ubuntu Security Notice USN-7106-1

Discussion in 'News Aggregator' started by Packet Storm, 19 Nov 2024.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 7106-1 - It was discovered that Tomcat did not include the secure attribute for session cookies when using the RemoteIpFilter with requests from a reverse proxy. An attacker could possibly use this issue to leak sensitive information. It was discovered that Tomcat had a vulnerability in its FORM authentication feature, leading to an open redirect attack. An attacker could possibly use this issue to perform phishing attacks.

    Continue reading...
     

Share This Page

Loading...