Security Advisory
CVE-2024-30155
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).