Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Spiceworks Sub-domain TRACE Vulnerability

$
0
0

Publish Date: Jan. 11, 2019

Summary

We've identified and fixed a vulnerability within a Spiceworks sub-domain that, when used alongside other potential vulnerabilities, could allow an attacker to steal users’ cookies.

Who’s Affected?

At this time we do not believe anyone was impacted by this vulnerability.

Details

A Spiceworks sub-domain that would not expect user traffic was utilizing HTTP TRACE. This is a method used for testing to see the data at the other end of a request chain. While this specific TRACE method would not normally be an issue on this sub-domain, when paired with other cross-domain vulnerabilities, an attacker could steal users’ cookies. One specific example of this type of attack is called Cross-Site Tracing, utilizing XSS and TRACE vulnerabilities.

Mitigating Factors

In order to use this vulnerability, an attacker...


Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>