Lucene search

K
redhatcveRedhat.comRH:CVE-2016-7153
HistoryOct 24, 2016 - 8:17 a.m.

CVE-2016-7153

2016-10-2408:17:23
redhat.com
access.redhat.com
16

EPSS

0.005

Percentile

77.6%

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a “HEIST” attack.

Mitigation

Disable third-party cookies in the browser.

<https://support.mozilla.org/en-US/kb/disable-third-party-cookies&gt; (Firefox)
<https://support.google.com/chrome/answer/95647?hl=en&gt; (Google Chrome)

EPSS

0.005

Percentile

77.6%