disclosure of IP address in cookie

Gruber Bernhard SAI sIT Bernhard.Gruber at s-itsolutions.at
Fri Jul 5 05:40:09 EDT 2013


During a security test of our shibboleth base solution, the following issue was reported to us:

Finding
The iDP component discloses an internal IP address in the value of the _idp_lc_session cookie. The truncated and base64 decoded value of the cookie is as follows.
127.0.0.1|<sessionID>
Risk
The disclosed information might help an attacker in formulating further attacks.
Recommendation
Management should review to options to change the affected cookie value.


Is there a possibility to remove the IP-Address from the cookie?




More information about the users mailing list