CVE-2021-3882
published 2021-10-14CVE-2021-3882: LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse…
PriorityP337medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
0.94%
57.4th percentile
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positioned to eavesdrop on the network traffic between the client and the server *and* the user must be tricked into using unencrypted HTTP traffic. Proper audit control and separation of duties limit Integrity impact of the attack vector. Users of LedgerSMB 1.8 are urged to upgrade to known-fixed versions. Users of LedgerSMB 1.7 or 1.9 are unaffected by this vulnerability and don't need to take action. As a workaround, users may configure their Apache or Nginx reverse proxy to add the Secure attribute at the network boundary instead of relying on LedgerSMB. For Apache, please refer to the 'Header always edit' configuration command in the mod_headers module. For Nginx, please refer to the 'proxy_cookie_flags' configuration command.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ledgersmb | — | — |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-1ubuntu0.1 | 1.6.33+ds-1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-2.1ubuntu0.1 | 1.6.33+ds-2.1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.3.46-1ubuntu0.1~esm1 | 1.3.46-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.4.42+ds-1ubuntu0.1~esm1 | 1.4.42+ds-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-1ubuntu0.1+esm1 | 1.6.9+ds-1ubuntu0.1+esm1 |
| ledgersmb | ledgersmb | >= 1.8.0 < 1.8.22 | 1.8.22 |
| ledgersmb | ledgersmb_ledgersmb | >= 1.8.0 < unspecified | unspecified |
| ledgersmb | ledgersmb_ledgersmb | unspecified – 1.8.21 | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv9.6CRITICAL
vendor_ubuntu8.8HIGH
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LedgerSMB vulnerabilities
vendor_ubuntu·2025-07-17·CVSS 8.8
CVE-2021-3731 [HIGH] LedgerSMB vulnerabilities
Title: LedgerSMB vulnerabilities
Summary: Several security issues were fixed in LedgerSMB.
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker
Debian
CVE-2021-3882: ledgersmb - LedgerSMB does not set the 'Secure' attribute on the session authorization cooki...
vendor_debian·2021·CVSS 6.8
CVE-2021-3882 [MEDIUM] CVE-2021-3882: ledgersmb - LedgerSMB does not set the 'Secure' attribute on the session authorization cooki...
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positio
OSV
ledgersmb vulnerabilities
osv·2025-07-17·CVSS 9.6
CVE-2021-3693 [CRITICAL] ledgersmb vulnerabilities
ledgersmb vulnerabilities
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker could possibly use this issue to
obtain sensitive information. Th
GHSA
GHSA-q34c-v76q-8jx6: LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reve
ghsa_unreviewed·2022-05-24
CVE-2021-3882 [MEDIUM] CWE-311 GHSA-q34c-v76q-8jx6: LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reve
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positio
OSV
CVE-2021-3882: LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reve
osv·2021-10-14·CVSS 6.8
CVE-2021-3882 [MEDIUM] CVE-2021-3882: LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reve
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positio
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ledgersmb/ledgersmb/commit/c242f5a2abf4b99b0da205473cbba034f306bfe2https://huntr.dev/bounties/7061d97a-98a5-495a-8ba0-3a4c66091e9dhttps://ledgersmb.org/cve-2021-3882-sensitive-non-secure-cookiehttps://github.com/ledgersmb/ledgersmb/commit/c242f5a2abf4b99b0da205473cbba034f306bfe2https://huntr.dev/bounties/7061d97a-98a5-495a-8ba0-3a4c66091e9dhttps://ledgersmb.org/cve-2021-3882-sensitive-non-secure-cookie
2021-10-14
Published