CVE-2014-4692: Infoleak
Published Jul 2, 2014
·Updated
pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Affected Software
1 affected component
Netgate pfSense<=2.1.3
Event History
Jul 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4692?
CVE-2014-4692 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-4692?
To fix CVE-2014-4692, upgrade pfSense to version 2.1.4 or higher.
3
What systems are affected by CVE-2014-4692?
CVE-2014-4692 affects pfSense versions prior to 2.1.4.
4
What type of vulnerability is CVE-2014-4692?
CVE-2014-4692 is a cookie vulnerability that lacks the HTTPOnly flag.
5
What are the risks associated with CVE-2014-4692?
The risks associated with CVE-2014-4692 include potential exposure of session cookies to remote attackers.