In rdiffweb prior to version 2.4.6, the cookie session_id does not have a secure attribute when the URL is invalid. Version 2.4.6 contains a fix for the issue.
{
"nvd_published_at": "2022-09-21T17:15:00Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-311",
"CWE-614"
],
"github_reviewed_at": "2022-09-22T22:52:16Z",
"github_reviewed": true
}