CVE Vulnerabilities

CVE-2026-32745

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Mar 13, 2026 | Modified: Mar 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Potential Mitigations

References