216.73.216.233

CVE-2025-12031

· Published 21/10/2025 18:15 · Modified 21/10/2025 19:31

Labels: CVE-2025-12031 2025-10-21CVE-2025-12031CWE-1004a0340c66-c385-4f8b-991b-3d05f6fd5220

Essential information

Published
21/10/2025 18:15
Modified
21/10/2025 19:31
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
a0340c66-c385-4f8b-991b-3d05f6fd5220
NVD
View on NVD

Affected products (CPE)

ProductCPE
blu / blu-ic2 cpe:2.3:a:blu:blu-ic2:*:*:*:*:*:*:*:*
blu / blu-ic4 cpe:2.3:a:blu:blu-ic4:*:*:*:*:*:*:*:*

References