CVE Vulnerabilities

CVE-2024-43173

Sensitive Cookie with Improper SameSite Attribute

Published: Oct 22, 2024 | Modified: Oct 25, 2024
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

Name Vendor Start Version End Version
Concert Ibm 1.0.0 (including) 1.0.0 (including)
Concert Ibm 1.0.1 (including) 1.0.1 (including)

Potential Mitigations

References