Red Hat Bugzilla – Bug 1086000
CVE-2014-0174 cumin: session cookies lack httponly setting
Last modified: 2014-11-07 09:53:01 EST
It was found that Cumin did not set the HttpOnly flag on session cookies. This could allow a malicious script to access the session cookie, which could make it easier to conduct Cross-Site Scripting (XSS) attacks.
Acknowledgements: This issue was discovered by Stanislav Graf of Red Hat.
IssueDescription: It was found that Cumin did not set the HttpOnly flag on session cookies. This could allow a malicious script to access the session cookie.
This issue has been addressed in following products: MRG for RHEL-5 v. 2 Via RHSA-2014:0859 https://rhn.redhat.com/errata/RHSA-2014-0859.html
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2014:0858 https://rhn.redhat.com/errata/RHSA-2014-0858.html