disclosure of IP address in cookie
Gruber Bernhard SAI sIT
Bernhard.Gruber at s-itsolutions.at
Fri Jul 5 05:40:09 EDT 2013
During a security test of our shibboleth base solution, the following issue was reported to us:
Finding
The iDP component discloses an internal IP address in the value of the _idp_lc_session cookie. The truncated and base64 decoded value of the cookie is as follows.
127.0.0.1|<sessionID>
Risk
The disclosed information might help an attacker in formulating further attacks.
Recommendation
Management should review to options to change the affected cookie value.
Is there a possibility to remove the IP-Address from the cookie?
More information about the users
mailing list