MEDIUM
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb
Published Sep 21, 2022
6.9
MEDIUMCVSS 4.0
EPSS 0.55%
Description
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<2.4.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Ikus060 | Ikus060/rdiffweb | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0236 Advisory
- https://github.com/advisories/GHSA-m748-hjqg-rpp8 Advisory
- https://github.com/ikus060/rdiffweb/commit/ac334dd27ceadac0661b1e2e059a8423433c3fee x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-287.yaml
- https://huntr.dev/bounties/39889a3f-8bb7-448a-b0d4-a18c671bbd23 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3250
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0236 | Advisory | |
| https://github.com/advisories/GHSA-m748-hjqg-rpp8 | Advisory | |
| https://github.com/ikus060/rdiffweb/commit/ac334dd27ceadac0661b1e2e059a8423433c3fee | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-287.yaml | ||
| https://huntr.dev/bounties/39889a3f-8bb7-448a-b0d4-a18c671bbd23 | x_refsource_CONFIRMExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3250 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Sep 21, 2022
Updated May 28, 2025
Reserved Sep 20, 2022
Link CVE-2022-3250
CISA Vulnrichment
Updated May 28, 2025
ENISA EUVD
EUVD-2022-0236 GHSA-M748-HJQG-RPP8 Assigner @huntrdev
Published Sep 21, 2022
Updated May 28, 2025
Exploited since n/a
Link EUVD-2022-0236