Missing Encryption of Sensitive Data in LedgerSMB - CVE-2021-3882
Published: November 4, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. A remote attacker can trick a user into using an unencrypted connection (HTTP) to obtain the authentication data by capturing network traffic.
Affected software
Ubuntu
ledgersmb (Ubuntu package)
Planning Analytics Local
IBM Planning Analytics Workspace
How to mitigate CVE-2021-3882
ledgersmb (Ubuntu package) - addressed in versions 1.3.46-1ubuntu0.1~esm1, 1.4.42+ds-1ubuntu0.1~esm1, 1.6.9+ds-1ubuntu0.1+esm1, 1.6.33+ds-1ubuntu0.1, 1.6.33+ds-2.1ubuntu0.1, 1.6.33+ds-2.2ubuntu0.25.04.1
Planning Analytics Local - update to 2.0.9.11
IBM Planning Analytics Workspace - update to 2.0.72