CVE-2014-0174: Infoleak
Published Jul 11, 2014
·Updated
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected Software
1 affected component
redhat Enterprise MRG=2.5
Event History
Jul 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0174?
CVE-2014-0174 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-0174?
To address CVE-2014-0174, you should update Red Hat Enterprise MRG to the latest version that includes the HTTPOnly flag for session cookies.
3
What vulnerabilities does CVE-2014-0174 expose?
CVE-2014-0174 exposes session cookies to potential theft via cross-site scripting attacks.
4
In which software is CVE-2014-0174 found?
CVE-2014-0174 is found in Red Hat Enterprise MRG version 2.5.
5
Has CVE-2014-0174 been remediated by Red Hat?
Yes, Red Hat has released security updates to remediate CVE-2014-0174.