cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 05 Oct 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 04 Oct 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain. | |
Title | cookie accepts cookie name, path, and domain with out of bounds characters | |
Weaknesses | CWE-74 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-04T19:09:46.640Z
Updated: 2024-10-04T20:14:56.059Z
Reserved: 2024-09-30T21:28:53.231Z
Link: CVE-2024-47764
Vulnrichment
Updated: 2024-10-04T20:14:49.745Z
NVD
Status : Awaiting Analysis
Published: 2024-10-04T20:15:07.310
Modified: 2024-10-07T17:48:28.117
Link: CVE-2024-47764
Redhat