dubbo-admin
dubbo-admin copied to clipboard
[Security] Console cookie security problem
Environment
- Deploy env: all
- Dubbo application version: all
- Registry: all
Issue description
Here are the security issues find by white hat hackers
- Pprof is opened to 0.0.0.0
- Login information is written in cookie, and token is hard coded
- Cookie is not secureonlyu
Logs
Click me to check logs
Copy logs to here.