EPSS
Percentile
22.7%
A flaw was found where 3scale did not set the HTTPOnly attribute on the user session cookie. An attacker could abuse this flaw to conduct Cross-site Scripting attacks and gain access to unauthorized information.
bugzilla.redhat.com/show_bug.cgi?id=1712167
nvd.nist.gov/vuln/detail/CVE-2019-14849
www.cve.org/CVERecord?id=CVE-2019-14849