#VU99654 Missing Encryption of Sensitive Data in LedgerSMB - CVE-2021-3882
Published: November 4, 2024
LedgerSMB
LedgerSMB
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. A remote attacker can trick a user into using an unencrypted connection (HTTP) to obtain the authentication data by capturing network traffic.