Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v4x-g74w-cgg6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

EPSS

Процентиль: 43%
0.00528
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-201
CWE-79

Связанные уязвимости

CVSS3: 4.6
redhat
больше 6 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

CVSS3: 5.4
nvd
больше 6 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

EPSS

Процентиль: 43%
0.00528
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-201
CWE-79