Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

rdiffweb has insecure HTTP cookies

GHSA-m748-hjqg-rpp8 · CVE-2022-3250 · PYSEC-2022-287

Published · Modified

Description

In rdiffweb prior to version 2.4.6, the cookie session_id does not have a secure attribute when the URL is invalid. Version 2.4.6 contains a fix for the issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes