CVE Vulnerabilities

CVE-2025-27223

Sensitive Cookie Without 'HttpOnly' Flag

Published: Oct 27, 2025 | Modified: Oct 31, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

Weakness

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Affected Software

Name Vendor Start Version End Version
Trufusion_enterprise Rocketsoftware * 7.10.4.0 (including)

Potential Mitigations

References