CVE-2014-0174
published 2014-07-11CVE-2014-0174: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.58%
73.0th percentile
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cumin: session cookies lack httponly setting
vendor_redhat·2014-04-10·CVSS 4.3
CVE-2014-0174 [MEDIUM] cumin: session cookies lack httponly setting
cumin: session cookies lack httponly setting
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
It was found that Cumin did not set the HttpOnly flag on session cookies. This could allow a malicious script to access the session cookie.
GHSA
GHSA-p88m-27c7-422h: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2
ghsa_unreviewed·2022-05-13
CVE-2014-0174 [MEDIUM] CWE-200 GHSA-p88m-27c7-422h: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
No detection rules found.
No public exploits indexed.
2014-07-11
Published