Back

MEDIUM

Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure prefix

Published Dec 22, 2022

Description

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Dec 22, 2022
Updated Apr 15, 2025
Reserved Sep 19, 2022

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Sep 20, 2022
Bugzilla 2128794

ENISA EUVD

Assigner mozilla
Published Dec 22, 2022
Updated Apr 15, 2025

GitHub

No data