VYPR

CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

VariantDraft

Description

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102

CVEs mapped to this weakness (67)

page 3 of 4
  • CVE-2024-39734MedJul 14, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2023-46179MedMar 15, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent…

  • CVE-2023-42016MedFeb 9, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this…

  • CVE-2015-3207MedJul 7, 2022
    risk 0.28cvss 5.3epss 0.01

    In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

  • CVE-2016-11076MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.

  • CVE-2023-0055MedJan 4, 2023
    risk 0.27cvss 5.3epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

  • CVE-2022-3250MedSep 21, 2022
    risk 0.27cvss 5.3epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.

  • CVE-2024-30142LowNov 7, 2024
    risk 0.25cvss 3.8epss 0.00

    HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.

  • CVE-2026-11956LowJun 11, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can lead to sensitive cookie without secure attribute. The attack can be launched…

  • CVE-2025-36249LowOct 31, 2025
    risk 0.24cvss 3.7epss 0.00

    IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2024-0349LowJan 9, 2024
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to sensitive cookie without secure attribute. The attack can be launched remotely. The…

  • CVE-2026-48058MedJul 28, 2026
    risk 0.23cvss epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator…

  • CVE-2025-52614LowOct 12, 2025
    risk 0.23cvss 3.5epss 0.00

    HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either directly or via another web site.

  • CVE-2025-52608LowJun 4, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

  • CVE-2023-5035LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to…

  • CVE-2021-35236LowOct 27, 2021
    risk 0.20cvss 3.1epss 0.01

    The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed…

  • CVE-2018-25060LowDec 30, 2022
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack may be launched remotely.…

  • CVE-2026-65655LowAug 11, 2026
    risk 0.08cvss epss 0.00

    When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can…

  • CVE-2026-56581LowJul 21, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

  • CVE-2024-23572MedJul 17, 2026
    risk 0.00cvss 4.2epss 0.00

    HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.