PT-2022-7817 · Red Hat · Openshift Origin
Govulnbot
+1
·
Published
2022-07-07
·
Updated
2024-08-21
·
CVE-2015-3207
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Openshift Origin version 3
Description
The issue is related to insecure cookies being set in the console of Openshift Origin. Specifically, the cookies lack 'secure' and 'HttpOnly' attributes.
Recommendations
For Openshift Origin version 3, consider configuring the console to set secure cookies with 'secure' and 'HttpOnly' attributes to mitigate the risk. As a temporary workaround, restrict access to sensitive data transmitted via cookies until a proper fix is applied.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openshift Origin