CVE-2019-17104

HIGH7.5EPSS 0.08%

Centreon Does Not Set HTTPOnly Flag

Published: 5/24/2022Modified: 2/16/2024
Also known as:GHSA-j224-7qr4-8646

Description

In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (5)