Several domains on kaspersky.com are vulnerable to Web Cache Deception attack
Team Summary
Official summary from Kaspersky
Reported security issue allowed a potential attacker to steal potentially sensitive information of users of a website, because multiple subdomains of the Kaspersky domain were vulnerable to web cache deception attack. In this scenario the user needs to open a phishing link in a web browser. The issue was fixed by changing settings which now only caches files for a specific address, allowing to avoid a situation in which the data of a cached page can be transmitted to any person upon repeated request of a previously vulnerable address. Note that this problem is related to our internal services and doesn't require any actions from side of our users.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Storage of Sensitive Information