Loading HuntDB...

Several domains on kaspersky.com are vulnerable to Web Cache Deception attack

Medium
K
Kaspersky
Submitted None

Team Summary

Official summary from Kaspersky

Reported security issue allowed a potential attacker to steal potentially sensitive information of users of a website, because multiple subdomains of the Kaspersky domain were vulnerable to web cache deception attack. In this scenario the user needs to open a phishing link in a web browser. The issue was fixed by changing settings which now only caches files for a specific address, allowing to avoid a situation in which the data of a cached page can be transmitted to any person upon repeated request of a previously vulnerable address. Note that this problem is related to our internal services and doesn't require any actions from side of our users.

Reported by golim

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Storage of Sensitive Information