CVE-2024-6739: Openfind MailGates and MailAudit - Sensitive Cookie Without 'HttpOnly' Flag
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Openfind MailAuditto a version that resolves this vulnerability.Fixed in 6.1.7.040 - Upgrade
Upgrade
Openfind MailGatesto a version that resolves this vulnerability.Fixed in 6.1.7.040
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6739?
CVE-2024-6739 is classified as a medium severity vulnerability due to the risk of session cookie theft via XSS attacks.
How do I fix CVE-2024-6739?
To mitigate CVE-2024-6739, enable the HttpOnly flag on session cookies in the affected versions of MailGates and MailAudit.
What are the affected versions for CVE-2024-6739?
CVE-2024-6739 affects versions of MailGates and MailAudit prior to 6.1.7.040.
Can CVE-2024-6739 lead to account takeover?
Yes, CVE-2024-6739 can lead to account takeover since attackers may steal session cookies and impersonate legitimate users.
Is there a known exploit for CVE-2024-6739?
As of now, there are no publicly known exploits specifically targeting CVE-2024-6739, but it remains a potential risk.