CVE-2013-7436

noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kanaka:novnc:0.4:*:*:*:*:*:*:*

History

21 Nov 2024, 02:00

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2015-0788.html - () http://rhn.redhat.com/errata/RHSA-2015-0788.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0833.html - () http://rhn.redhat.com/errata/RHSA-2015-0833.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0834.html - () http://rhn.redhat.com/errata/RHSA-2015-0834.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0884.html - () http://rhn.redhat.com/errata/RHSA-2015-0884.html -
References () http://www.openwall.com/lists/oss-security/2015/02/17/1 - () http://www.openwall.com/lists/oss-security/2015/02/17/1 -
References () http://www.openwall.com/lists/oss-security/2015/03/12/13 - () http://www.openwall.com/lists/oss-security/2015/03/12/13 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1193451 - () https://bugzilla.redhat.com/show_bug.cgi?id=1193451 -
References () https://github.com/kanaka/noVNC/commit/ad941faddead705cd611921730054767a0b32dcd - () https://github.com/kanaka/noVNC/commit/ad941faddead705cd611921730054767a0b32dcd -

Information

Published : 2015-04-10 14:59

Updated : 2024-11-21 02:00


NVD link : CVE-2013-7436

Mitre link : CVE-2013-7436

CVE.ORG link : CVE-2013-7436


JSON object : View

Products Affected

kanaka

  • novnc
CWE
CWE-310

Cryptographic Issues