Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-7436

Опубликовано: 28 окт. 2013
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

It was discovered that noVNC did not properly set the 'secure' flag when issuing cookies. An attacker could use this flaw to intercept cookies via a man-in-the-middle attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3novncNot affected
OpenStack 4 for RHEL 6novncFixedRHSA-2015:088423.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6novncFixedRHSA-2015:083316.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7novncFixedRHSA-2015:083416.04.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7novncFixedRHSA-2015:078807.04.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=1193451novnc: session hijack through insecurely set session token cookies

EPSS

Процентиль: 69%
0.00614
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

nvd
почти 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

debian
почти 11 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https ...

github
больше 3 лет назад

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS

Процентиль: 69%
0.00614
Низкий

6.8 Medium

CVSS2