Firefox Vulnerability: Incorrect Checking of Cookie Prefixes

CVE-2024-5699
Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Firefox
Vendor
CVE Published:
11 June 2024

Summary

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

Affected Version(s)

Firefox < 127

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Konstantin Preißer
.