-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: None
-
Component/s: None
cert.fr@cassidian.com reported the following vulnerability:
== Type ==
Information Disclosure
== Product ==
Atlassian Crowd
== Severity ==
Medium
== Description ==
The crowd.token_key cookie, used as a token to authenticate on all Atlassian applications, is marked as HttpOnly.
However, the Crowd 500 error page (/crowd/console/500.jsp) displays this cookie?s value, breaking the HttpOnly behavior.