Metrics
Affected Vendors & Products
Mon, 18 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0. | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow an actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0. |
Mon, 18 Nov 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0. | |
Title | Session Hijacking in Firebase JavaScript SDK | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-11-18T15:02:10.044Z
Reserved: 2024-11-08T13:51:36.349Z
Link: CVE-2024-11023

Updated: 2024-11-18T15:02:03.791Z

Status : Awaiting Analysis
Published: 2024-11-18T11:15:05.507
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-11023

No data.