PT-2024-40303 · Artax · Artax

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions artax versions prior to 1.0.6 artax versions 2 prior to 2.0.6
Description The issue allowed cookies of foo.bar.example.com to be leaked to foo.bar. Furthermore, any site could set cookies for any other site. This was resolved by artax following newer browser implementations, which now restrict cookie setting to domains higher or equal to the current domain, excluding public suffixes.
Recommendations For artax versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue. For artax versions 2 prior to 2.0.6, update to version 2.0.6 or later to resolve the issue.

Related Identifiers

GHSA-GM98-G2WF-7C68

Affected Products

Artax