7.5
CVE-2019-17104
- EPSS 0.08%
- Veröffentlicht 08.10.2019 13:15:15
- Zuletzt bearbeitet 21.11.2024 04:31:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Centreon ≫ Centreon Vm Version <= 19.04.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.23 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-565 Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.