CVE-2024-47833

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 9, 2024
Updated: Oct 16, 2024
CWE ID 732
CWE ID 319
CWE ID 614
CWE ID 1004

Summary

CVE-2024-47833 is a vulnerability affecting Taipy, an open-source Python library for data scientists and machine learning engineers. The issue lies in the library's handling of session cookies, which are served without the Secure and HTTPOnly flags in affected versions. This omission makes cookies susceptible to interception and theft through insecure connections or cross-site scripting attacks. Users are advised to upgrade to version 4.0.0 to mitigate this risk, as there are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share