Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39293
HistoryFeb 16, 2023 - 7:44 a.m.

Authorization Bypass

2023-02-1607:44:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
52
authorization
bypass
vulnerable
browser
subdomain
cookie
application
compromised

0.001 Low

EPSS

Percentile

21.7%

werkzeug is vulnerable to Authorization Bypass. A vulnerable browser may allow a compromised application on an adjacent subdomain to set a cookie like =__Host-test=bad for another subdomain, when the browser accepts nameless cookies such as =value instead of key=value, resulting in application seeing the bad cookie value but the valid cookie key.