-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
This is to improve mitigation of XSS vulnerabilities.
[CWD-2938] Set Crowd JSESSIONID as HTTPOnly in the default configuration
Workflow | Original: Simplified Crowd Development Workflow v2 - restricted [ 1509400 ] | New: JAC Bug Workflow v3 [ 3364557 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: Simplified Crowd Development Workflow v2 [ 1391301 ] | New: Simplified Crowd Development Workflow v2 - restricted [ 1509400 ] |
Workflow | Original: Crowd Development Workflow v2 [ 410112 ] | New: Simplified Crowd Development Workflow v2 [ 1391301 ] |
Labels | Original: security | New: no-advisory-required security |
Assignee | New: joe [ jwalton ] |
Fix Version/s | New: 2.5.2 [ 28296 ] | |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Resolved [ 5 ] |
For existing installations, the Crowd Context in apache-tomcat/conf/Catalina/localhost/crowd.xml needs to be edited from:
to