Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmpx-vghf-2xp6

Опубликовано: 01 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

EPSS

Процентиль: 38%
0.0017
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

EPSS

Процентиль: 38%
0.0017
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-732