PT-2024-6081 · Mozilla+4 · Firefox+4

Konstantin Preißer

·

Published

2024-06-11

·

Updated

2025-03-21

·

CVE-2024-5699

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 127
Description The issue is related to the incorrect handling of cookie prefixes such as Secure due to case-sensitive comparison, which should be case-insensitive according to the specification. This could lead to the browser not honoring the behaviors specified by the prefix. The vulnerability may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 127, update to version 127 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10126
ALT-PU-2024-10593
ALT-PU-2024-13895
ALT-PU-2024-15839
BDU:2024-06924
CVE-2024-5699
OESA-2025-1322
OESA-2025-1323
OPENSUSE-SU-2024:14044-1
OPENSUSE-SU-2024:14572-1
USN-6862-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu