GHSA-gm98-g2wf-7c68

Suggest an improvement
Source
https://github.com/advisories/GHSA-gm98-g2wf-7c68
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-gm98-g2wf-7c68/GHSA-gm98-g2wf-7c68.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gm98-g2wf-7c68
Published
2024-05-15T17:52:00Z
Modified
2024-11-29T05:25:36Z
Summary
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Details

In artax version before 1.0.6 and 2 before 2.0.6, cookies of foo.bar.example.com were leaked to foo.bar. Additionally, any site could set cookies for any other site. Artax fixed this issue by following newer browser implementations now. Cookies can only be set on domains higher or equal to the current domain, but not on any public suffixes.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-15T17:52:00Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Packagist / amphp/artax

Package

Name
amphp/artax
Purl
pkg:composer/amphp/artax

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2
Fixed
2.0.6

Affected versions

v2.*
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
2.*
2.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-gm98-g2wf-7c68/GHSA-gm98-g2wf-7c68.json"

Packagist / amphp/artax

Package

Name
amphp/artax
Purl
pkg:composer/amphp/artax

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.6

Affected versions

v0.*
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.*
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-gm98-g2wf-7c68/GHSA-gm98-g2wf-7c68.json"