Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11709
HistoryJan 15, 2019 - 9:06 a.m.

Cookie Leak

2019-01-1509:06:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.006 Low

EPSS

Percentile

78.0%

libcurl.so is vulnerable to cookie leak. A remote attacker is able to set or send arbitrary cookies for certain sites. libcurl.so parses IP addresses similar to domain names, where a site with an IP address of 192.168.0.1 can set or send cookies for another site ending with .168.0.1.

References