CVE-2010-4312

EPSS 1.7%

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

發布日:2022/5/14修改日:2024/2/8

描述

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

受影響套件(1)

參考連結(6)