In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.vde.com/en-us/advisories/vde-2021-027 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERTVDE
Published: 2021-08-31T10:32:58.577856Z
Updated: 2024-09-17T04:14:32.706Z
Reserved: 2021-06-10T00:00:00
Link: CVE-2021-34563
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-31T11:15:07.583
Modified: 2024-11-21T06:10:41.803
Link: CVE-2021-34563
Redhat
No data.