BIT-codeigniter-2022-39284

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/codeigniter/BIT-codeigniter-2022-39284.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-codeigniter-2022-39284
Aliases
Published
2024-03-06T10:53:32.698Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting $secure or $httponly value to true in Config\Cookie is not reflected in set_cookie() or Response::setCookie(). As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not affect session cookies. Users are advised to upgrade to v4.2.7 or later. Users unable to upgrade are advised to manually construct their cookies either by setting the options in code or by constructing Cookie objects. Examples of each workaround are available in the linked GHSA.

Database specific
{
    "cpes": [
        "cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / codeigniter

Package

Name
codeigniter
Purl
pkg:bitnami/codeigniter

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.2.7