CVE Vulnerabilities

CVE-2015-3207

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Jul 07, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu

In Openshift Origin 3 the cookies being set in console have no secure, HttpOnly attributes.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

Name Vendor Start Version End Version
Origin Openshift 3.0.0 (including) 3.0.0 (including)

Potential Mitigations

References