View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 15142 | Bug reports | Security | public | 2019-08-07 14:53 | 2021-07-12 14:04 |
| Reporter | ma77ie | Assigned To | c_schmitz | ||
| Priority | none | Severity | minor | ||
| Status | closed | Resolution | fixed | ||
| Product Version | 3.17.x | ||||
| Summary | 15142: Limesurvey has Missing Cookie Security Attributes | ||||
| Description | Limesurvey creates cookies that have weak attributes which compromises their security. In particular PHPSESSID cookie doesn't have SameSite set and YII_CSRF_TOKEN doesn't have HttpOnly & SameSite set. | ||||
| Steps To Reproduce | View cookies in a browser, for example in FireFox select Web Developer / Storage Inspector from the menu and view cookies. Yellow box on attached screenshot shows HttpOnly and/or SameSite attributes not set for these cookies. | ||||
| Tags | No tags attached. | ||||
| Attached Files | |||||
| Bug heat | 254 | ||||
| Complete LimeSurvey version number (& build) | 3.17.9+190731 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | MySQL 5.7.20 | ||||
| Server OS (if known) | |||||
| Webserver software & version (if known) | |||||
| PHP Version | 7.0.33 | ||||
|
Please update to the latest version and check if the bug can still be reproduced. Thank you. |
|
|
Hello ma77ie, c_schmitz |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2019-08-07 14:53 | ma77ie | New Issue | |
| 2019-08-07 14:53 | ma77ie | File Added: limesurvey cookies.png | |
| 2019-08-08 21:28 | jelo | Relationship added | related to 14769 |
| 2019-09-04 14:08 | cdorin | Assigned To | => c_schmitz |
| 2019-09-04 14:08 | cdorin | Status | new => assigned |
| 2021-03-10 22:59 | ollehar | Status | assigned => feedback |
| 2021-03-10 22:59 | ollehar | Note Added: 63233 | |
| 2021-07-12 14:04 | c_schmitz | Status | feedback => closed |
| 2021-07-12 14:04 | c_schmitz | Resolution | open => fixed |
| 2021-07-12 14:04 | c_schmitz | Note Added: 65376 |