CVE Vulnerabilities

CVE-2023-4055

Published: Aug 01, 2023 | Modified: Aug 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

When the number of cookies per domain was exceeded in document.cookie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 116.0 (excluding)
Firefox_esr Mozilla 102.0 (including) 102.14 (excluding)
Firefox_esr Mozilla 115.0 (including) 115.1 (excluding)

References