Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
History

Wed, 05 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Mar 2025 09:00:00 +0000

Type Values Removed Values Added
Description Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
Title Improper cookie attributes in Foreseer Reporting Software (FRS)
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published: 2025-03-05T08:53:59.122Z

Updated: 2025-03-05T14:50:42.281Z

Reserved: 2025-01-07T09:41:16.734Z

Link: CVE-2025-22493

cve-icon Vulnrichment

Updated: 2025-03-05T14:50:37.276Z

cve-icon NVD

Status : Received

Published: 2025-03-05T09:15:10.443

Modified: 2025-03-05T09:15:10.443

Link: CVE-2025-22493

cve-icon Redhat

No data.