Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4rw-7xwx-x53p

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.

EPSS

Процентиль: 67%
0.00539
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 11 лет назад

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.

debian
около 11 лет назад

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a S ...

EPSS

Процентиль: 67%
0.00539
Низкий

Дефекты

CWE-200