PT-2022-28257 · Softwarex · Softwarex

Published

2022-10-10

·

Updated

2022-10-10

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions SoftwareX versions prior to 2.2.1
Description The issue is related to the default cookie name prefix, which was set to Host instead of Host-. This prefix is used for additional security to ensure the cookie came from the correct domain when no domain option is provided in the cookie options.
Recommendations For versions prior to 2.2.1, as a temporary workaround, consider providing a custom cookieName as part of the options, which is correctly prefixed with Host-. Upgrade to version 2.2.1 or later to fully resolve the issue.

Related Identifiers

GHSA-JJMG-X456-W976

Affected Products

Softwarex