First published: Wed Dec 16 2020(Updated: )
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | >=9.0.0<=10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this BigFix Inventory vulnerability is CVE-2020-14248.
The title of this BigFix Inventory vulnerability is 'BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session'.
The severity level of this BigFix Inventory vulnerability is medium.
This BigFix Inventory vulnerability affects BigFix Inventory up to v10.0.2 by not setting the secure flag for the session cookie in an https session.
This BigFix Inventory vulnerability can be exploited by remote attackers capturing the session cookie which is sent in http requests.
Yes, a fix is available for this BigFix Inventory vulnerability. Please refer to the referenced link for more information.