Lucene search

K
hackeroneHaxatron1H1:1565615
HistoryMay 11, 2022 - 7:02 a.m.

Internet Bug Bounty: CVE-2022-27779: cookie for trailing dot TLD

2022-05-1107:02:48
haxatron1
hackerone.com
65

0.001 Low

EPSS

Percentile

34.4%

Published Advisory: https://curl.se/docs/CVE-2022-27779.html

Original Report: https://hackerone.com/reports/1553301

Impact

This can allow arbitrary sites to set cookies that then would get sent to a different and unrelated site or domain. (ie. conduct session fixation attacks.)