CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Parent: CWE-319 - Cleartext Transmission of Sensitive Information

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

58 vulnerabilities with CWE-614
CVE-2021-27764 HIGH
HCL BigFix WebUI - Insecure Cookie Permission Assignment
CVSS 7.4
CVE-2021-35236 LOW
Kiwi Syslog Server <9.7.2 - Info Disclosure
CVSS 3.1
CVE-2021-3882 MEDIUM
LedgerSMB 1.8.0-1.8.21 - Sensitive Cookie Without 'Secure' Attribute
CVSS 6.8
CVE-2020-29024 MEDIUM
Secomea GateManager <9.3 - Info Disclosure
CVSS 5.3
CVE-2020-27651 MEDIUM
Synology Router Manager <1.2.4-8081 - Info Disclosure
CVSS 5.8
CVE-2020-27650 MEDIUM
Synology DSM <6.2.3-25426-2 - Info Disclosure
CVSS 5.8
CVE-2018-25060 LOW
go-macaron/csrf < 0.0.0-20180426211050-dadd1711a617 - Sensitive Cookie Without Secure Attribute
CVSS 3.7
CVE-2015-3207 MEDIUM
Openshift Origin 3 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 58