CVE Vulnerabilities

CVE-2021-27764

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: May 06, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

NameVendorStart VersionEnd Version
Bigfix_webuiHcltech- (including)- (including)

Potential Mitigations

References