CVE-2024-5699: Critical severity firefox vulnerability
In violation of spec, cookie prefixes such as Secure were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix.
Other sources
In violation of spec, cookie prefixes such as Secure were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
— Launchpad
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5699?
CVE-2024-5699 has been classified with a moderate severity due to its potential to cause unexpected behavior in cookie handling.
What versions of Firefox are affected by CVE-2024-5699?
CVE-2024-5699 affects Mozilla Firefox versions up to but not including 127.
How do I fix CVE-2024-5699?
To remediate CVE-2024-5699, update Firefox to version 127 or higher.
Can CVE-2024-5699 impact cookie security?
Yes, CVE-2024-5699 can impact cookie security as it may result in improper handling of cookie prefixes.
Is any Debian package affected by CVE-2024-5699?
Yes, the Debian firefox package version 131.0.3-1 is affected by CVE-2024-5699.