Описание
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| bionic | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| cosmic | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| devel | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| disco | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| esm-apps/bionic | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| esm-apps/xenial | not-affected | 1:0.4+dfsg+1+20131010+gitf68af8af3d-4 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
| lucid | DNE | |
| precise | ignored | end of life |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
noVNC before 0.5 does not set the secure flag for a cookie in an https ...
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
EPSS
4.3 Medium
CVSS2