Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38112
HistoryNov 19, 2022 - 6:49 p.m.

Authentication Bypass

2022-11-1918:49:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
firefox
vulnerability
authentication
serviceworker
fetchevent
samesite cookie policy
attacker
security.

EPSS

0.001

Percentile

43.1%

firefox is vulnerable to authentication bypass. The vulnerability exists when a ServiceWorker intercepted a request with FetchEvent which allows an attacker to bypass SameSite cookie policy by sending malicious requests.