NA

CVE-2023-29547

Published: 02/06/2023 Updated: 09/06/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla focus

mozilla firefox esr

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2023-13 Security Vulnerabilities fixed in Firefox 112, Firefox for Android 112, Focus for Android 112 Announced April 11, 2023 Impact high Products Firefox, Firefox for Android, Focus for Android Fixed in ...