elemental-cms@1.1.36 vulnerabilities

Flask + MongoDB Web CMS for Developers.

  • latest version

    1.1.42

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    3 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the elemental-cms package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Sensitive Cookie in HTTPS Session Without "Secure" Attribute

    elemental-cms is a Flask + MongoDB Web CMS for Developers.

    Affected versions of this package are vulnerable to Sensitive Cookie in HTTPS Session Without "Secure" Attribute via the mongosessioninterface.py file, which could cause the user agent to send those cookies in plaintext over an HTTP session.

    How to fix Sensitive Cookie in HTTPS Session Without "Secure" Attribute?

    Upgrade elemental-cms to version 1.1.39 or higher.

    [,1.1.39)