Логотип exploitDog
bind:CVE-2015-8470
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-8470

Количество 2

Количество 2

nvd логотип

CVE-2015-8470

около 8 лет назад

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q6x9-v42r-65c3

больше 3 лет назад

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-8470

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

CVSS3: 6.5
0%
Низкий
около 8 лет назад
github логотип
GHSA-q6x9-v42r-65c3

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу