Описание
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
A flaw was found in guzzlehttp/guzzle. The software does not correctly enforce the "host-only" scope for cookies, which means it stores the request host in the cookie's domain field instead of restricting the cookie to the exact host. This vulnerability could allow an attacker who controls a subdomain (a "child host") to access cookies intended only for the main domain (the "parent host"). Consequently, sensitive information such as user session identifiers or authorization tokens might be disclosed if the same cookie storage is used across different security boundaries.
Отчет
No Red Hat products ship guzzlehttp/guzzle. Community builds of nextcloud and roundcubemail in Fedora and EPEL ship patched versions (7.15.2 and 7.15.3 respectively, fix version is 7.15.1).
Меры по смягчению последствий
Upgrade guzzlehttp/guzzle to version 7.15.1 or later.
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...
Guzzle: Host-only cookie scope is not preserved
EPSS
5.9 Medium
CVSS3