CVE-2024-58317
A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-614
- Published
- 2025-12-18
- Last modified
- 2026-03-13
Affected products
- Kentico Xperience
Weakness type
Related vulnerabilities
- CVE-2026-65655 — Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy
- CVE-2026-15656 — IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
- CVE-2026-48058 — nebula-mesh: Session and OIDC state cookies lack the Secure attribute
- CVE-2026-56581 — HCL MyCloud was affected with Cookie Attribute Path Not Set
- CVE-2024-23572 — HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may...
- CVE-2026-57948 — Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
- CVE-2026-46550 — NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
- CVE-2026-53661 — boruta-server sent sensitive session cookies without the Secure attribute