Executive brief
Boruta, an authorization server used for managing user identities and logins, failed to properly secure its session and 'remember me' cookies. This flaw allows an attacker who can monitor a user's network traffic to steal these cookies if they are sent over an unencrypted connection. If successful, the attacker could impersonate the user and gain unauthorized access to their account and associated services.
Technical details
Boruta (prior to version 0.9.1) fails to set the 'Secure' attribute on sensitive cookies, including the shared session cookie (_boruta_web_key) and the identity remember-me cookie (_boruta_identity_web_user_remember_me). This vulnerability (CWE-614) occurs in the boruta_web, boruta_identity, and boruta_admin components. An attacker positioned to intercept network traffic (e.g., on an insecure Wi-Fi network) can capture these cookies if the browser transmits them over plaintext HTTP. This enables session hijacking and user impersonation. The fix, introduced in version 0.9.1 (commit 18691c6), enforces 'secure: true' and 'same_site: "Lax"' for these cookies.
Affected products
- malach-it Boruta Server <= 0.9.0
Timeline
- 2026-06-10: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: CVE-2026-53661 published to NVD
- 2026-06-11: patched: Fixed in version 0.9.1