CVE-2015-3155
14.08.2015, 18:59
Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Enginsight
Vendor | Product | Version |
---|---|---|
theforeman | foreman | 𝑥 ≤ 1.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References