CVE-2015-3207
published 2022-07-07CVE-2015-3207: In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.69%
48.6th percentile
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | openshift_origin | >= 0 < 1.0.0 | 1.0.0 |
| openshift | origin | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insecure cookies in Openshift Origin in github.com/openshift/origin
osv·2024-08-21
CVE-2015-3207 Insecure cookies in Openshift Origin in github.com/openshift/origin
Insecure cookies in Openshift Origin in github.com/openshift/origin
Insecure cookies in Openshift Origin in github.com/openshift/origin
OSV
Insecure cookies in Openshift Origin
osv·2022-07-08
CVE-2015-3207 [MEDIUM] Insecure cookies in Openshift Origin
Insecure cookies in Openshift Origin
In Openshift Origin the cookies being set in console have no 'secure', 'HttpOnly' attributes.
GHSA
Insecure cookies in Openshift Origin
ghsa·2022-07-08
CVE-2015-3207 [MEDIUM] CWE-311 Insecure cookies in Openshift Origin
Insecure cookies in Openshift Origin
In Openshift Origin the cookies being set in console have no 'secure', 'HttpOnly' attributes.
Red Hat
github.com/openshift/origin: Insecure cookies in Openshift Origin in github.com/openshift/origin
vendor_redhat·2020-07-07·CVSS 5.3
CVE-2015-3207 [MEDIUM] CWE-311 github.com/openshift/origin: Insecure cookies in Openshift Origin in github.com/openshift/origin
github.com/openshift/origin: Insecure cookies in Openshift Origin in github.com/openshift/origin
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
A flaw was found in OpenShift Origin. This vulnerability may allow unauthorized access and manipulation of the console via interception and manipulation of cookies.
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: openshift-logging/logging-curator5-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: openshift4/ose-tests (Red Hat OpenShift Container Platform 4) - Not affected
Package: container-native-virtualization/cluster-network-addons-operator (Red Hat OpenShift Virtualization 4) - Not affected
Package: con
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-07
Published