Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3106 | cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain. |
Github GHSA |
GHSA-pxg6-pf52-xh8x | cookie accepts cookie name, path, and domain with out of bounds characters |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Oct 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 04 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain. | |
| Title | cookie accepts cookie name, path, and domain with out of bounds characters | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-04T20:14:56.059Z
Reserved: 2024-09-30T21:28:53.231Z
Link: CVE-2024-47764
Updated: 2024-10-04T20:14:49.745Z
Status : Awaiting Analysis
Published: 2024-10-04T20:15:07.310
Modified: 2024-10-07T17:48:28.117
Link: CVE-2024-47764
OpenCVE Enrichment
No data.
EUVD
Github GHSA