Логотип exploitDog
bind:CVE-2024-30155
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-30155

Количество 2

Количество 2

nvd логотип

CVE-2024-30155

11 месяцев назад

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26m8-335m-qj22

11 месяцев назад

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-30155

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-26m8-335m-qj22

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу