It was found that Cumin did not set the HttpOnly flag on session cookies. This could allow a malicious script to access the session cookie, which could make it easier to conduct Cross-Site Scripting (XSS) attacks.
Acknowledgements: This issue was discovered by Stanislav Graf of Red Hat.
IssueDescription: It was found that Cumin did not set the HttpOnly flag on session cookies. This could allow a malicious script to access the session cookie.
This issue has been addressed in following products: MRG for RHEL-5 v. 2 Via RHSA-2014:0859 https://rhn.redhat.com/errata/RHSA-2014-0859.html
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2014:0858 https://rhn.redhat.com/errata/RHSA-2014-0858.html