CVE-2019-25091
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack remotely. The name of the patch is 60a3fe559c453bc36b0ec3e5dd39c1303640a59a. It is recommended to apply a patch to fix this issue. The identifier VDB-216909 was assigned to this vulnerability.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0025
Percentile
0,5th
Updated
EPSS Score Trend (Last 91 Days)
1004
Sensitive Cookie Without 'HttpOnly' Flag
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Web Based, Web Server
Application
Nsupdate.Info by Nsupdate
Version Range Affected
To
2019-05-19
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:nsupdate:nsupdate.info:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/nsupdate-info/nsupdate.info/commit/60a3fe559c453bc36b0ec3e5d…
https://github.com/nsupdate-info/nsupdate.info/pull/410
https://vuldb.com/?ctiid.216909
https://vuldb.com/?id.216909
https://github.com/nsupdate-info/nsupdate.info/commit/60a3fe559c453bc36b0ec3e5d…
https://github.com/nsupdate-info/nsupdate.info/pull/410
https://vuldb.com/?ctiid.216909
https://vuldb.com/?id.216909