Firefox Vulnerability: Incorrect Checking of Cookie Prefixes

CVE-2024-5699

Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Firefox
Vendor
CVE Published:
11 June 2024

Summary

In violation of spec, cookie prefixes such as __Secure were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

Affected Version(s)

Firefox < 127

Refferences

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Konstantin Preißer
.