CVE-2024-8644
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).This issue affects ValeApp: before v2.0.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.27%
- CWE
- CWE-315
- Published
- 2024-09-27
- Last modified
- 2026-06-02
Affected products
- Oceanic Software ValeApp
Weakness type
Related vulnerabilities
- CVE-2025-8528 — Exrick xboot getMenuList sensitive information in a cookie
- CVE-2025-4537 — yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
- CVE-2024-24768 — 1Panel set-cookie is missing the Secure keyword
- CVE-2021-34564 — In WirelessHART-Gateway versions 3.0.9 a vulnerability allows to read and write sensitive data in a cookie
- CVE-2018-19941 — Cleartext Storage of Sensitive Information in Cookies