Description
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-5972 | A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.075Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14849
No data.
Status : Modified
Published: 2019-12-12T14:15:15.257
Modified: 2024-11-21T04:27:29.613
Link: CVE-2019-14849
OpenCVE Enrichment
No data.
EUVD