7.6 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
References
-
Researcher Disclosure issue-tracking
-
https://www.vulncheck.com/advisories/pinpoint-insecure-session-cookie-attribute… third-party-advisory
Affected products
- =<3.1.0
Matching in nixpkgs
pkgs.pinpoint
Tool for making hackers do excellent presentations
pkgs.haskellPackages.amazonka-pinpoint
Amazon Pinpoint SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python312Packages.mypy-boto3-pinpoint
None
pkgs.python313Packages.mypy-boto3-pinpoint
Type annotations for boto3 pinpoint
pkgs.python314Packages.mypy-boto3-pinpoint
Type annotations for boto3 pinpoint
pkgs.haskellPackages.amazonka-pinpoint-email
Amazon Pinpoint Email Service SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.haskellPackages.amazonka-pinpoint-sms-voice
Amazon Pinpoint SMS and Voice Service SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.mypy-boto3-pinpoint-email
Type annotations for boto3 pinpoint-email
pkgs.python314Packages.mypy-boto3-pinpoint-email
Type annotations for boto3 pinpoint-email
pkgs.python313Packages.types-aiobotocore-pinpoint
Type annotations for aiobotocore pinpoint
pkgs.haskellPackages.amazonka-pinpoint-sms-voice-v2
Amazon Pinpoint SMS Voice V2 SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.mypy-boto3-pinpoint-sms-voice
Type annotations for boto3 pinpoint-sms-voice
pkgs.python314Packages.mypy-boto3-pinpoint-sms-voice
Type annotations for boto3 pinpoint-sms-voice
pkgs.python313Packages.mypy-boto3-pinpoint-sms-voice-v2
Type annotations for boto3 pinpoint-sms-voice-v2
pkgs.python313Packages.types-aiobotocore-pinpoint-email
Type annotations for aiobotocore pinpoint-email
pkgs.python314Packages.mypy-boto3-pinpoint-sms-voice-v2
Type annotations for boto3 pinpoint-sms-voice-v2
pkgs.python313Packages.types-aiobotocore-pinpoint-sms-voice
Type annotations for aiobotocore pinpoint-sms-voice
Package maintainers
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>