View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
15142 | Bug reports | Security | public | 2019-08-07 14:53 | 2021-07-12 14:04 |
Reporter | ma77ie | Assigned To | c_schmitz | ||
Priority | none | Severity | minor | ||
Status | closed | Resolution | fixed | ||
Product Version | 3.17.x | ||||
Summary | 15142: Limesurvey has Missing Cookie Security Attributes | ||||
Description | Limesurvey creates cookies that have weak attributes which compromises their security. In particular PHPSESSID cookie doesn't have SameSite set and YII_CSRF_TOKEN doesn't have HttpOnly & SameSite set. | ||||
Steps To Reproduce | View cookies in a browser, for example in FireFox select Web Developer / Storage Inspector from the menu and view cookies. Yellow box on attached screenshot shows HttpOnly and/or SameSite attributes not set for these cookies. | ||||
Tags | No tags attached. | ||||
Attached Files | |||||
Bug heat | 254 | ||||
Complete LimeSurvey version number (& build) | 3.17.9+190731 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | MySQL 5.7.20 | ||||
Server OS (if known) | |||||
Webserver software & version (if known) | |||||
PHP Version | 7.0.33 | ||||
Please update to the latest version and check if the bug can still be reproduced. Thank you. |
|
Hello ma77ie, c_schmitz |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2019-08-07 14:53 | ma77ie | New Issue | |
2019-08-07 14:53 | ma77ie | File Added: limesurvey cookies.png | |
2019-08-08 21:28 | jelo | Relationship added | related to 14769 |
2019-09-04 14:08 | cdorin | Assigned To | => c_schmitz |
2019-09-04 14:08 | cdorin | Status | new => assigned |
2021-03-10 22:59 | ollehar | Status | assigned => feedback |
2021-03-10 22:59 | ollehar | Note Added: 63233 | |
2021-07-12 14:04 | c_schmitz | Status | feedback => closed |
2021-07-12 14:04 | c_schmitz | Resolution | open => fixed |
2021-07-12 14:04 | c_schmitz | Note Added: 65376 |