CVE-2016-5409: Red Hat Openshift

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.

Affected products

  • Red Hat Openshift: version 2.0 only

Published 2017-04-20. Last modified 2026-06-17.