PT-2017-3677 · Mozilla+2 · Firefox+2

Inko

·

Publicado

2017-11-28

·

Atualizado

2024-12-12

·

CVE-2018-5114

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 58
Description: The issue is related to errors in the implementation of cookie storage in Mozilla Firefox. It allows a remote attacker to access HttpOnly cookies using a crafted HTTP request. When an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. However, network requests correctly use the changed HttpOnly cookie.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider closing all documents after changing a cookie to "HttpOnly" to prevent script access to the original value. Restrict access to sensitive information stored in cookies to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00868
CVE-2018-5114
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Produtos afetados

Alt Linux
Firefox
Ubuntu