PT-2023-22871 · Samsung · Samsung Internet

Mohit Raj

+1

·

Publicado

2023-07-06

·

Atualizado

2023-07-12

·

CVE-2023-30674

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Internet versions prior to 21.0.0.41
Description The issue is related to an improper configuration that allows an attacker to bypass SameSite Cookie restrictions. This could potentially lead to security breaches, although specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For versions prior to 21.0.0.41, update to version 21.0.0.41 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-30674

Produtos afetados

Samsung Internet