Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-40958
HistoryDec 22, 2022 - 8:15 p.m.

Session fixation

2022-12-2220:15:00
PRIOn knowledge base
www.prio-n.com
4
session fixation
cookie injection
shared subdomain
secure context
vulnerability
firefox esr
thunderbird
firefox

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.6%

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.