Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp26-q6wq-vrfp

Опубликовано: 09 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

EPSS

Процентиль: 24%
0.00082
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-311
CWE-614
CWE-79

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

EPSS

Процентиль: 24%
0.00082
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-311
CWE-614
CWE-79