Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cg3q-59w7-rvc2

Опубликовано: 29 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Reliance on Cookies without Validation and Integrity Checking in getgrav/grav

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking. A cookie with an overly broad path can be accessed through other applications on the same domain. Since cookies often carry sensitive information such as session identifiers, sharing cookies across applications can lead a vulnerability in one application to cause a compromise in another.

Пакеты

Наименование

getgrav/grav

composer
Затронутые версииВерсия исправления

< 1.7.21

1.7.21

EPSS

Процентиль: 52%
0.00294
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

EPSS

Процентиль: 52%
0.00294
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-565