PT-2022-7817 · Red Hat · Openshift Origin

·

CVE-2015-3207

·

Published

2022-07-07

·

Updated

2024-08-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Openshift Origin version 3
Description The issue is related to insecure cookies being set in the console of Openshift Origin. Specifically, the cookies lack 'secure' and 'HttpOnly' attributes.
Recommendations For Openshift Origin version 3, consider configuring the console to set secure cookies with 'secure' and 'HttpOnly' attributes to mitigate the risk. As a temporary workaround, restrict access to sensitive data transmitted via cookies until a proper fix is applied.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3207
GHSA-RQPH-25Q9-9JHP
GO-2022-0505

Affected Products

Openshift Origin