In violation of spec, cookie prefixes such as `__Secure`...
Critical severity
Unreviewed
Published
Jun 11, 2024
to the GitHub Advisory Database
•
Updated Aug 12, 2024
Description
Published by the National Vulnerability Database
Jun 11, 2024
Published to the GitHub Advisory Database
Jun 11, 2024
Last updated
Aug 12, 2024
In violation of spec, cookie prefixes such as
__Secure
were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.References