CVE-2019-25091 is a medium-severity vulnerability affecting nsupdate.info, specifically within the CSRF Cookie Handler component. It stems from improper handling of the CSRF_COOKIE_HTTPONLY argument in src/nsupdate/settings/base.py, leading to a cookie being set without the 'httponly' flag. This allows for remote exploitation, potentially enabling an attacker to access sensitive cookie information. The CVSS score of 5.3 (Medium) indicates a network-based attack with low complexity, requiring no user interaction, and resulting in low confidentiality impact. While the EPSS score is very low, suggesting minimal exploitability in the wild, the FAUCET Risk Score of 19/100 indicates some level of concern. Currently, there is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also absent, which is typical for the vast majority of vulnerabilities. A patch (60a3fe559c453bc36b0ec3e5dd39c1303640a59a) is available to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019-05-19CPE matchmatch criteria | cpe:2.3:a:nsupdate:nsupdate.info:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.