CWE-614
62 CVEs • Abstraction: Variant
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.
CVEs (62)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission...Show more |
1Synology 2Diskstation Manager Skynas FirmwareJun 17, 2026 Oct 29, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its trans...Show more |