CVE Vulnerabilities

CVE-2024-2493

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Apr 23, 2024 | Modified: Apr 23, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.1-00.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.

Potential Mitigations

References