CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Configurations

No configuration.

History

16 Jul 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-32/ -
Summary (en) A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128. (en) A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

11 Jul 2024, 15:06

Type Values Removed Values Added
CWE CWE-1275
Summary
  • (es) Un iframe anidado, que activa una navegación entre sitios, podría enviar cookies SameSite=Strict o Lax. Esta vulnerabilidad afecta a Firefox &lt; 128.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

09 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 15:15

Updated : 2024-07-16 18:15


NVD link : CVE-2024-6611

Mitre link : CVE-2024-6611

CVE.ORG link : CVE-2024-6611


JSON object : View

Products Affected

No product.

CWE
CWE-1275

Sensitive Cookie with Improper SameSite Attribute