In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
JetBrains·CWE-614·Published 2026-03-13