Insecure Defaults
Affecting invenio-app-ils package, versions [,1.0.0a28)
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
invenio-app-ils is an Invenio App ILS.
Affected versions of this package are vulnerable to Insecure Defaults. Cookies were found to be set without security configuration.
Remediation
Upgrade invenio-app-ils
to version 1.0.0a28 or higher.
CVSS Score
2.6
low severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredLow
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- Credit
- Unknown
- CWE
- CWE-453
- Snyk ID
- SNYK-PYTHON-INVENIOAPPILS-1090201
- Disclosed
- 01 Apr, 2021
- Published
- 01 Apr, 2021