Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v4x-g74w-cgg6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

EPSS

Процентиль: 59%
0.00374
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-201
CWE-79

Связанные уязвимости

CVSS3: 4.6
redhat
около 6 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

CVSS3: 5.4
nvd
около 6 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

EPSS

Процентиль: 59%
0.00374
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-201
CWE-79