CVE-2026-32745
EUVD-2026-1204513.03.2026, 19:55
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settingsEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jetbrains | datalore | 𝑥 < 2026.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-614 - Sensitive Cookie in HTTPS Session Without 'Secure' AttributeThe Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.