Red Hat Bugzilla – Bug 1366461
CVE-2016-5409 OSE 2 cookie does not set httponly
Last modified: 2016-09-07 15:10:41 EDT
It is reported that when OpenShift Enterprise 2 creates the GEARID cookie it fails to set the HTTPONLY valud on the cookie making it possible for attackers to read the cookie through other flaws.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.