Answers is vulnerable to BREACH (SSL/HTTP gzip) attack

XMLWordPrintable

    • Severity 3 - Minor

      NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      This is an external report, and not a high priority - certainly much lower impact than ANSWERS-648.

      This issue was reported by Nakul Mohan <edwardmaya618@gmail.com>, 11 May - the email is too long to reproduce here.

      An attacker with the ability to:

      1. Inject partial chosen plaintext into a victim's requests
      2. Measure the size of encrypted traffic
        can leverage information leaked by compression to recover targeted parts of the plaintext.

      This can be attacked by using the reflected values in /search/ to leak the CSRF token.

            Assignee:
            Dennis Kromhout van der Meer (Inactive)
            Reporter:
            Dougall Johnson
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: