Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4964

Опубликовано: 20 авг. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 5

Описание

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

РелизСтатусПримечание
devel

not-affected

lucid

ignored

end of life
precise

not-affected

quantal

not-affected

raring

not-affected

upstream

not-affected

Показывать по

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

debian
больше 12 лет назад

Puppet Enterprise before 3.0.1 does not set the secure flag for the se ...

github
больше 3 лет назад

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

5 Medium

CVSS2