Skip to main content
Participant
April 21, 2021
Question

Cleartext Storage of Sensitive Information in a Cookie on Admin Page

  • April 21, 2021
  • 1 reply
  • 237 views

we have security vulnarability found in penetration testing :

Cleartext Storage of Sensitive Information in a Cookie

page- administrator/index.cfm

coldfusion version 11

 

This app is using base64 encoding for admin console cookies. Base64 encoding is only making it harder to decode, therefore provides only weak protection mechanism. Cookies therefore include admin password. Also as is described in other parts of report this cookie is exchanged via unencrypted channel.
Resolution
Instead of using base64 encoded plaintext with password use some random string to authenticate valid admin privilege session.

 

Question - can someone help how to fix this it?

    This topic has been closed for replies.

    1 reply

    BKBK
    Community Expert
    Community Expert
    April 21, 2021

    A suggestion. Open the ColdFusion Administrator and go to Server Settings > Memory Variables. Scroll to the bottom of the page. Select the strongest cookie security settings.