CVE-2014-0174

Severity
4.3MEDIUM
EPSS
0.2%
top 53.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11
Latest updateMay 13

Description

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-p88m-27c7-422h: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 22022-05-13
CVEList
CVE-2014-0174: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 22014-07-11

📋Vendor Advisories

1
Red Hat
cumin: session cookies lack httponly setting2014-04-10

💬Community

1
Bugzilla
CVE-2014-0174 cumin: session cookies lack httponly setting2014-04-09
CVE-2014-0174 (MEDIUM CVSS 4.3) | Cumin (aka MRG Management Console) | cvebase.io