PT-2022-7817 · Red Hat · Openshift Origin

Govulnbot

+1

·

Published

2022-07-07

·

Updated

2024-08-21

·

CVE-2015-3207

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Openshift Origin version 3
Description The issue is related to insecure cookies being set in the console of Openshift Origin. Specifically, the cookies lack 'secure' and 'HttpOnly' attributes.
Recommendations For Openshift Origin version 3, consider configuring the console to set secure cookies with 'secure' and 'HttpOnly' attributes to mitigate the risk. As a temporary workaround, restrict access to sensitive data transmitted via cookies until a proper fix is applied.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2015-3207
GHSA-RQPH-25Q9-9JHP
GO-2022-0505

Affected Products

Openshift Origin