CVE-2021-35236
Last modified
CVE-2021-35236 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the application can be accessed over both HTTP, there is a potential for the cookie can be sent in clear text.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Kiwi Syslog Server | <= 9.7.2 |
References
- https://documentation.solarwinds.com/en/success_center/kss/content/release_notes/kss_9-8_release_notes.htmRelease Notes, Vendor Advisory
- https://documentation.solarwinds.com/en/success_center/kss/content/release_notes/kss_9-8_release_notes.htmRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35236?
How severe is CVE-2021-35236?
How do I fix CVE-2021-35236?
Are you affected by CVE-2021-35236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
