Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-53861

Опубликовано: 10 июл. 2025
Источник: redhat
CVSS3: 3.1

Описание

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.

Меры по смягчению последствий

Currently, there is no mitigation available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/gateway-rhel8-operatorUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2379360aap: Sensitive Cookie(s) Set Without Security Flags

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
27 дней назад

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.

CVSS3: 3.1
github
26 дней назад

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.

3.1 Low

CVSS3