Skip to content

[Security] Console cookie security problem #1336

@robocanic

Description

@robocanic

Environment

  • Deploy env: all
  • Dubbo application version: all
  • Registry: all

Issue description

Here are the security issues find by white hat hackers

  1. Pprof is opened to 0.0.0.0
  2. Login information is written in cookie, and token is hard coded
  3. Cookie is not secureonlyu

Logs

Click me to check logs
Copy logs to here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions