PT-2022-8303 · Unknown · Nsupdate.Info

CVE-2019-25091

·

Published

2022-12-27

·

Updated

2026-07-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions nsupdate.info (affected versions not specified)
Description A problematic vulnerability has been found in nsupdate.info, affecting the component CSRF Cookie Handler in the file src/nsupdate/settings/base.py. The manipulation of the argument CSRF COOKIE HTTPONLY leads to a cookie without the httponly flag. This issue can be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch, specifically the one with the name 60a3fe559c453bc36b0ec3e5dd39c1303640a59a. As a temporary workaround, consider restricting the manipulation of the CSRF COOKIE HTTPONLY argument to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25091
GHSA-MWVP-QR62-CVJX
PYSEC-2026-885

Affected Products

Nsupdate.Info