CWE-1004
Sensitive Cookie Without 'HttpOnly' Flag
Description
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (46)
page 3 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2876 | Low | 0.20 | 3.1 | 0.00 | Jun 13, 2023 | Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0… | ||
| CVE-2019-25091 | Low | 0.17 | 3.7 | 0.01 | Dec 27, 2022 | A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag.… | ||
| CVE-2026-57948 | Med | 0.00 | 6.8 | 0.00 | Jun 29, 2026 | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP.… | ||
| CVE-2022-4630 | Med | 0.00 | 5.3 | 0.01 | Dec 21, 2022 | Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. | ||
| CVE-2021-3706 | Hig | 0.00 | 7.5 | 0.01 | Sep 15, 2021 | adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag | ||
| CVE-2010-4312 | 0.00 | — | 0.02 | Nov 26, 2010 | The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie. |
- risk 0.20cvss 3.1epss 0.00
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0…
- risk 0.17cvss 3.7epss 0.01
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag.…
- risk 0.00cvss 6.8epss 0.00
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP.…
- risk 0.00cvss 5.3epss 0.01
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
- risk 0.00cvss 7.5epss 0.01
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
- CVE-2010-4312Nov 26, 2010risk 0.00cvss —epss 0.02
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.