CVE-2024-5699
11.06.2024, 13:15
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 127.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||
mozjs102 |
| ||||||||||
mozjs38 |
| ||||||||||
mozjs52 |
| ||||||||||
mozjs68 |
| ||||||||||
mozjs78 |
| ||||||||||
mozjs91 |
| ||||||||||
thunderbird |
|
Common Weakness Enumeration