It has been discovered that cookies created in the Install Tool are not hardened to be submitted only via HTTP. In combination with other vulnerabilities such as cross-site scripting it can lead to hijacking an active and valid session in the Install Tool.
{ "nvd_published_at": null, "cwe_ids": [ "CWE-1004" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-30T15:11:42Z" }