Please support flags for Secure / HttpOnly Cookies

Bug #1118160 reported by Jesse Pretorius
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
haproxy (Ubuntu)
Fix Released
Low
Unassigned

Bug Description

HAProxy contains a weakness due to not supporting certain security-related flags for cookies. By not supporting the 'Secure' or 'HttpOnly' cookies, applications behind the proxy become more susceptible to cookie stealing attacks.

The solution is to upgrade to version 1.5-DEV11 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

More detail here: http://osvdb.org/82768

Please work on updating the Ubuntu packages to v1.5 asap.

description: updated
information type: Private Security → Public
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and filing a bug.

This was a security feature that was added to 1.4.22. This doesn't seem like a vulnerability so much as a missing security feature. If you would like to have this in Ubuntu, I suggest creating, testing and submitting a patch to the development release as per https://wiki.ubuntu.com/SponsorshipProcess. If your would like to have this available in a stable release of Ubuntu, once your patch has been incorporated into the development release of Ubuntu, please follow https://wiki.ubuntu.com/StableReleaseUpdates.

For your reference, this is the commit in question for 1.4:
http://haproxy.1wt.eu/git?p=haproxy-1.4.git;a=commit;h=81e2376ab3d2ee3ee3e30f0ea7714c395a4f8ecb

and for 1.5:
http://haproxy.1wt.eu/git?p=haproxy.git;a=commit;h=4992dd2d307aefd288379d2fefcf5a87b7631b75

summary: - HAProxy Secure / HttpOnly Flag Cookie Weakness
+ Please support flags for Secure / HttpOnly Cookies
Changed in haproxy (Ubuntu):
status: New → Triaged
Revision history for this message
Mathew Hodson (mhodson) wrote :

HAProxy 1.5 is available in Wily, and 1.4.24 is available in Trusty, which should have this feature.

Changed in haproxy (Ubuntu):
importance: Undecided → Low
status: Triaged → Fix Released
tags: added: upgrade-software-version
Mathew Hodson (mhodson)
information type: Public → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.