Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in versio
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with htt
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or sessi
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern
When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to
Frequently Asked Questions
What is CWE-614?
CWE-614 (CWE-614) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-614?
There are 17 CVE records associated with CWE-614 in our database. Of these, 0 are critical severity, 0 are high severity, and 10 are medium severity.
How can I protect against CWE-614 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-614 using AI-powered security agents.
Detect CWE-614 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-614 vulnerabilities across your infrastructure.
Get Started