CVE-2013-7436

Impact:
Moderate
Public Date:
2013-10-28
CWE:
CWE-319
Bugzilla:
1193451: CVE-2013-7436 novnc: session hijack through insecurely set session token cookies
It was discovered that noVNC did not properly set the 'secure' flag when issuing cookies. An attacker could use this flaw to intercept cookies via a man-in-the-middle attack.

Find out more about CVE-2013-7436 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 6.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (novnc) RHSA-2015:0834 2015-04-16
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 (novnc) RHSA-2015:0788 2015-04-07
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 (novnc) RHSA-2015:0833 2015-04-16
Red Hat Enterprise Linux OpenStack Platform 4.0 (novnc) RHSA-2015:0884 2015-04-23

Affected Packages State

Platform Package State
RHEV Manager 3 novnc Not affected

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.