CVE Vulnerabilities

CVE-2019-8283

Sensitive Cookie Without 'HttpOnly' Flag

Published: Jun 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have HttpOnly flag. This allows malicious javascript to steal it.

Weakness

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Affected Software

NameVendorStart VersionEnd Version
Sentinel_ldkGemalto*7.92 (excluding)

Potential Mitigations

References