漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HCL iControl was affected by Missing Cookie Attributes vulnerability.
Vulnerability Description
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
HTTPS会话中未设置’Secure’属性的敏感Cookie
Vulnerability Title
HCL iControl 安全漏洞
Vulnerability Description
HCL iControl是印度HCL公司的一个IT基础设施监控与自动化运维平台。 HCL iControl存在安全漏洞,该漏洞源于缺少Cookie属性,包括Secure和SameSite,且路径设置为根目录。
CVSS Information
N/A
Vulnerability Type
N/A