Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cjq-gpfr-mw4c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

EPSS

Процентиль: 52%
0.00287
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 4.3
nvd
почти 6 лет назад

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

EPSS

Процентиль: 52%
0.00287
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-565