HIGH7.5
GHSA-j224-7qr4-8646
Centreon Does Not Set HTTPOnly Flag
Details
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
0No fixed version published yet for centreon/centreon (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-17104[ADVISORY]
- https://github.com/centreon/centreon-archived/issues/7097[WEB]
- https://docs.centreon.com/current/en/administration/secure-platform.html#securing-the-apache-web-server[WEB]
- https://github.com/centreon/centreon-archived[PACKAGE]
- https://www.openwall.com/lists/oss-security/2019/10/08/1[WEB]