CVE-2019-14849: Red Hat 3scale
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.
Affected products
- Red Hat 3scale: before 2.6 (fixed in 2.6)
Published 2019-12-12. Last modified 2026-06-17.