ipa_session cookie does not include "SameSite" flag. A customer complained about the error in scanning tool which reported this issue as CSRF.
Scanning tool detects this as vulnerability
(what happens) ipa_session cookie does not have "SameSite" flag
(what do you expect to happen) ipa_session cookie should include "SameSite" flag for CSRF prevention
$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server
Metadata Update from @ftrivino: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-70229
Metadata Update from @dhanina: - Issue assigned to dhanina
Metadata Update from @dhanina: - Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/8336
master:
ipa-4-8:
ipa-4-6:
ipa-4-13:
ipa-4-12:
ipa-4-9:
ipa-4-11:
ipa-4-10:
Metadata Update from @sumenon: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)