Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14849

Опубликовано: 11 дек. 2019
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

A flaw was found where 3scale did not set the HTTPOnly attribute on the user session cookie. An attacker could abuse this flaw to conduct Cross-site Scripting attacks and gain access to unauthorized information.

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=17121673scale: user session cookie does not set HTTPOnly

EPSS

Процентиль: 43%
0.00528
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 6 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

CVSS3: 5.4
github
больше 4 лет назад

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.

EPSS

Процентиль: 43%
0.00528
Низкий

4.6 Medium

CVSS3