{ "schema_version": "1.4.0", "id": "GHSA-qjw9-54p2-cgcx", "modified": "2025-04-09T03:50:38Z", "published": "2022-05-01T23:27:46Z", "aliases": [ "CVE-2008-0128" ], "details": "The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-0128" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39804" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E" }, { "type": "WEB", "url": "http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" }, { "type": "WEB", "url": "http://issues.apache.org/bugzilla/show_bug.cgi?id=41217" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2008-0630.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/28549" }, { "type": "WEB", "url": "http://secunia.com/advisories/28552" }, { "type": "WEB", "url": "http://secunia.com/advisories/29242" }, { "type": "WEB", "url": "http://secunia.com/advisories/31493" }, { "type": "WEB", "url": "http://secunia.com/advisories/33668" }, { "type": "WEB", "url": "http://security-tracker.debian.net/tracker/CVE-2008-0128" }, { "type": "WEB", "url": "http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" }, { "type": "WEB", "url": "http://www.debian.org/security/2008/dsa-1468" }, { "type": "WEB", "url": "http://www.redhat.com/support/errata/RHSA-2008-0261.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/500396/100/0/threaded" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/500412/100/0/threaded" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/27365" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2008/0192" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2009/0233" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2008-01-23T02:00:00Z" } }