Re: phppgadmin / CVE-2019-10784

Ola Lundqvist <ola@inguza.com> writes:

> I have ideas on how we can reduce the attack possibilities but I cannot
> find any perfect solution to this.

What about setting samesite=Lax in the session Cookie? This should solve
all problems for POST requests. Are there any vulnerable GET requests?
Additionally this is already the default for Chrome (I don't think
Firefox has done this yet though).


I posted this suggestion upstream also, but got no response - yet.

Only problem is older browsers won't be protected, I am not sure this is
a big issue however.

I imagine setting the samesite value will be a lot less invasive then
some of the other solutions being discussed here.

The other problem might be implementing this. I see PHP has a
session.cookie_samesite option but this was only implemented in PHP >=

