ZeroHour

CVE-2020-14248

CVSS 3.1
5.3 medium
EPSS
<1%p50
Published
()
Modified
Description

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Vendors
hcltech
Products
bigfix platform
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.