CVE-2022-27779: cookie for trailing dot TLD

Disclosed: 2022-06-11 18:58:33 By haxatron1 To ibb
Medium
Vulnerability Details
Published Advisory: https://curl.se/docs/CVE-2022-27779.html Original Report: https://hackerone.com/reports/1553301 ## Impact This can allow arbitrary sites to set cookies that then would get sent to a different and unrelated site or domain. (ie. conduct session fixation attacks.)
Actions
View on HackerOne
Report Stats
  • Report ID: 1565615
  • State: Closed
  • Substate: resolved
  • Upvotes: 27
Share this report