Forum Discussion
CVE-2004-0462 - Vulnerability Issue by Alertlogic
Hi,
CVE-2004-0462 - Vulnerability Issue by Alertlogic . Can this be mitigated by setting a "Secure" flag on the cookie attribute with an iRule. Kindly guide into this.
Thanks and Regards Parveez
4 Replies
- Vitaliy_Savrans
Nacreous
Hi, The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session. To fix this:
when HTTP_RESPONSE { set myValues [HTTP::cookie names] foreach mycookies $myValues { HTTP::cookie secure $mycookies enable } } - Parveez_70209
Nimbostratus
Hi Vitaliy,
Your solution helped, thank you.
Regards
- please flag it as answered then.
- Parveez_70209
Nimbostratus
Hi,
I just did it, thanks for letting me know about this.
Will definitely do in future posts too.
Thanks and Regards Parveez
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com