CVE Vulnerabilities

CVE-2024-30155

Sensitive Cookie with Improper SameSite Attribute

Published: Mar 26, 2025 | Modified: Oct 30, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

NameVendorStart VersionEnd Version
Hcl_sxHcltech21 (including)21 (including)

Potential Mitigations

References