Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
Vulnerability Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Vulnerability Type
HTTPS会话中未设置’Secure’属性的敏感Cookie
Vulnerability Title
Forgekeep nebula-mesh 会话机制问题漏洞
Vulnerability Description
Forgekeep nebula-mesh是Forgekeep团队的一系列网络代理和VPN整合软件。 Forgekeep nebula-mesh 0.3.2之前版本存在会话机制问题漏洞,该漏洞源于未在cookie中设置Secure标志,可能导致通过明文请求泄露会话。
CVSS Information
N/A
Vulnerability Type
N/A