Medium severity5.3NVD Advisory· Published May 5, 2021· Updated Jun 17, 2026
CVE-2021-29247
CVE-2021-29247
Description
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:btcpayserver:btcpay_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:btcpayserver:btcpay_server:*:*:*:*:*:*:*:*range: <=1.0.7.0
- (no CPE)range: <=1.0.7.0
- BTCPay Server/BTCPay Serverdescription
Patches
Vulnerability mechanics
References
2- blog.btcpayserver.org/vulnerability-disclosure-v1-0-7-0/nvdVendor Advisory
- github.com/btcpayserver/btcpayserver/releasesnvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.