Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63p2-gq7m-9wpm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.

EPSS

Процентиль: 46%
0.0023
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 13 лет назад

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.

EPSS

Процентиль: 46%
0.0023
Низкий

Дефекты

CWE-200