5
CVSSv2

CVE-2015-3155

Published: 14/08/2015 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Foreman prior to 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmission within an http session.

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman

Vendor Advisories

It was found that Foreman did not set the HttpOnly flag on session cookies This could allow a malicious script to access the session cookie ...