Elektrine lite

← Feed

@sash@hachyderm.io

Post #2101964

2026-05-06 09:08 UTC

RIPE NCC made session tokens for the entire member portal available to over 1000 third parties, by design. Full access to the RPKI dashboard, the RIPE Database, and everything else. RIPE NCC had placed strangers under the same domain as their most critical systems. The RIPE NCC SSO cookie is scoped to `*.ripe.net`, so browsers send it to any HTTPS server under that domain. Atlas anchor hosts and RIPE meeting attendees all had assigned hostnames under that domain, and nothing stopped them from requesting a valid TLS certificate for those hostnames. A single link click was enough to leak the token. The impact went further than my publication from last week with XSS+CSRF: this allows full session access, including adding admin users and API keys that persist silently. Full write-up: https://mxsasha.eu/posts/ripe-ncc-sso-cookie-exposure/ Resolved about 3 months after my report, by adding two DNS records. RIPE NCC has not published any acknowledgement of this vulnerability, nor credited me as the reporter on their own channels.

Replies (9)