CVE-2024-2756

CVSS V2 None CVSS V3 None
Description
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications. 
Overview
  • CVE ID
  • CVE-2024-2756
  • Assigner
  • php
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-29T03:34:16.912Z
  • Last Modified Date
  • 2024-04-29T03:34:16.912Z
History
Created Old Value New Value Data Type Notes
2024-06-25 23:25:38 Added to TrackCVE