CVE-2019-25091

Published: Dic 27, 2022 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2022-7693 Aliases: GHSA-mwvp-qr62-cvjx
ExploitDB:
Other exploit source:
Google Dorks:
LOW 3,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack remotely. The name of the patch is 60a3fe559c453bc36b0ec3e5dd39c1303640a59a. It is recommended to apply a patch to fix this issue. The identifier VDB-216909 was assigned to this vulnerability.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0025
Percentile
0,5th
Updated

EPSS Score Trend (Last 91 Days)

1004

Sensitive Cookie Without 'HttpOnly' Flag

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Application Data Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
Application

Nsupdate.Info by Nsupdate

Version Range Affected
To 2019-05-19 (exclusive)
cpe:2.3:a:nsupdate:nsupdate.info:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/nsupdate-info/nsupdate.info/commit/60a3fe559c453bc36b0ec3e5d…
https://github.com/nsupdate-info/nsupdate.info/pull/410
https://vuldb.com/?ctiid.216909
https://vuldb.com/?id.216909
Third Party Advisory
https://vuldb.com/?id.216909
https://github.com/nsupdate-info/nsupdate.info/commit/60a3fe559c453bc36b0ec3e5d…
https://github.com/nsupdate-info/nsupdate.info/pull/410
https://vuldb.com/?ctiid.216909
https://vuldb.com/?id.216909
Third Party Advisory
https://vuldb.com/?id.216909