Description
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
Scores
CVSS v3
7.5
EPSS
0.0008
EPSS Percentile
22.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-565
Status
published
Products (2)
centreon/centreon
0Packagist
centreon/centreon_vm
< 19.04.3
Published
Oct 08, 2019
Tracked Since
Feb 18, 2026