Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-27658
HistoryOct 29, 2020 - 9:15 a.m.

Design/Logic Flaw

2020-10-2909:15:00
PRIOn knowledge base
www.prio-n.com
5

5.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.7%

Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CPENameOperatorVersion
router_managerge1.2
router_managerlt1.2.4

5.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.7%

Related for PRION:CVE-2020-27658